CVE-2021-41366: Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20174Patch KB5007255 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20174Patch KB5007247 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4770Patch KB5007192 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23517Patch KB5007245 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19041.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19119Patch KB5007207 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.318Patch KB5007215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.350Patch KB5007205 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1916Patch KB5007189 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2300Patch KB5007206
Event History
Frequently Asked Questions
What is the severity of CVE-2021-41366?
The severity of CVE-2021-41366 is high with a CVSS score of 7.8.
Which software is affected by CVE-2021-41366?
Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows 8.1, Microsoft Windows RT 8.1, Microsoft Windows Server 2012, Microsoft Windows Server 2016, Microsoft Windows Server 2019, Microsoft Windows Server 2022.
How can I fix CVE-2021-41366?
Apply the security update provided by Microsoft as mentioned in the advisory: [CVE-2021-41366](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41366).
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-41366?
The Common Weakness Enumeration (CWE) ID for CVE-2021-41366 is 269.