CVE-2021-40477: Windows Event Tracing Elevation of Privilege Vulnerability
Published Oct 13, 2021
·Updated
Windows Event Tracing Elevation of Privilege Vulnerability
Affected Software
18 affected components
Microsoft Windows 10
Microsoft Windows 10=20h2
Microsoft Windows 10=21h1
Microsoft Windows 10=1607
Microsoft Windows 10=1809
Microsoft Windows 10=1909
Microsoft Windows 10=2004
Microsoft Windows 11
Microsoft Windows 11
Microsoft Windows 8.1
Microsoft Windows RT 8.1
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
Microsoft Windows Server 2016
Microsoft Windows Server 2016=20h2
Microsoft Windows Server 2016=2004
Microsoft Windows Server 2019
Microsoft Windows Server 2022
Remediation
Event History
Oct 13, 2021
CVE Published
via MITRE·12:27 AM
Data Sourced
via MITRE·12:27 AM
DescriptionSeverity
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who can exploit this vulnerability?
An attacker needs local access to an affected Windows system and low-level privileges. The CVSS vector indicates no user interaction is required.
2
What impact could successful exploitation have?
Successful exploitation could allow elevation of privilege and has high confidentiality, integrity, and availability impact according to the supplied CVSS metrics.
3
Which systems should be prioritized for remediation?
Prioritize Microsoft Windows 8.1, Windows RT 8.1, Windows 10, Windows 11, and the listed Windows Server releases: 2012, 2016, 2019, and 2022. A patch is available.