CVE-2021-34509: Storage Spaces Controller Information Disclosure Vulnerability
Storage Spaces Controller Information Disclosure Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1110Patch KB5004237 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19041.1110Patch KB5004237 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1679Patch KB5004245 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2061Patch KB5004244 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4530Patch KB5004238 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1110Patch KB5004237
Event History
Frequently Asked Questions
What is CVE-2021-34509?
CVE-2021-34509 is a vulnerability in the Storage Spaces Controller of Microsoft Windows 10 and Windows Server 2016/2019, which could allow an attacker to disclose sensitive information.
Which software is affected by CVE-2021-34509?
Microsoft Windows 10 versions 1607, 1809, 1909, 2004, 20H2, and 21H1, as well as Windows Server 2016 and 2019, are affected by CVE-2021-34509.
What is the severity of CVE-2021-34509?
CVE-2021-34509 has a severity rating of medium, with a CVSS score of 5.5.
How can an attacker exploit CVE-2021-34509?
An attacker can exploit CVE-2021-34509 to gain unauthorized access to sensitive information stored in the affected Storage Spaces Controller.
Is there a fix or patch available for CVE-2021-34509?
Yes, Microsoft has released a security patch to address the vulnerability. It is recommended to update the affected systems with the latest security updates.