CVE-2021-33765: Windows Installer Spoofing Vulnerability
Windows Installer Spoofing Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21167Patch KB5004299 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20069Patch KB5004298 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23409Patch KB5004302 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20069Patch KB5004285 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.25661Patch KB5004307 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4530Patch KB5004238 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19003Patch KB5004249 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1110Patch KB5004237 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19041.1110Patch KB5004237 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1110Patch KB5004237 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1679Patch KB5004245 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2061Patch KB5004244
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33765?
The severity of CVE-2021-33765 is rated as Important by Microsoft.
Is there a workaround for CVE-2021-33765?
Yes, disabling the Windows Installer service can mitigate the risk of CVE-2021-33765 until a patch is applied.
How do I fix CVE-2021-33765?
To fix CVE-2021-33765, apply the security update released by Microsoft for the affected Windows versions.
Which Windows versions are affected by CVE-2021-33765?
CVE-2021-33765 affects multiple versions of Windows, including Windows 7, Windows 10, Windows Server 2008, and later versions.
Can exploiting CVE-2021-33765 allow unauthorized access?
Yes, exploiting CVE-2021-33765 can allow an attacker to execute code with elevated privileges, leading to unauthorized access.