CVE-2021-26890: Application Virtualization Remote Code Execution Vulnerability
Application Virtualization Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.867Patch KB5000802 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1440Patch KB5000808 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.1817Patch KB5000822
Event History
Frequently Asked Questions
Which systems are identified as affected?
The listed affected software includes Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows Server 2019, and Microsoft Windows Server.
What access and interaction does exploitation require?
The CVSS vector rates the attack as local and requires user interaction. It does not require prior privileges or authentication.
What could a successful exploit affect?
The CVSS assessment assigns high impact to confidentiality, integrity, and availability. The listed CVSS 3.1 score is 7.8, rated high severity.