CVE-2021-33786: Windows LSA Security Feature Bypass Vulnerability
Windows LSA Security Feature Bypass Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.25661Patch KB5004307 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20069Patch KB5004285 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23409Patch KB5004302 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21167Patch KB5004299 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4530Patch KB5004238 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1110Patch KB5004237 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2061Patch KB5004244 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19041.1110Patch KB5004237
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this vulnerability?
The CVSS vector indicates that an attacker needs low-level privileges on the affected system. Exploitation does not require user interaction and can be performed over the network.
What is the potential impact if exploitation succeeds?
Successful exploitation can result in high impacts to confidentiality and integrity. The CVSS vector does not indicate an availability impact.
Which Windows Server versions are listed as affected?
The listed affected products are Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016, and 2019, along with a general Microsoft Windows Server entry.