CVE-2021-26891: Windows Container Execution Agent Elevation of Privilege Vulnerability
Windows Container Execution Agent Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.867Patch KB5000802 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4283Patch KB5000803 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1440Patch KB5000808 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.1817Patch KB5000822
Event History
Frequently Asked Questions
Does exploitation require network access or user interaction?
The CVSS vector indicates local attack access is required, and no user interaction is required. An attacker would also need low-level privileges before exploiting the issue.
What is the potential impact after successful exploitation?
Successful exploitation can affect confidentiality, integrity, and availability at a high level, according to the CVSS metrics. The issue is rated high severity with a CVSS 3.1 score of 7.8.
Which systems are identified as affected?
The listed affected products are Microsoft Windows 10, Windows Server 2016, Windows Server 2019, and Microsoft Windows Server. Specific affected versions or update levels are not provided in the available data.