CVE-2021-42282: Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20174Patch KB5007255 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23517Patch KB5007245 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.25769Patch KB5007233 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21282Patch KB5007246 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4770Patch KB5007192 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19041.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.350Patch KB5007205 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2300Patch KB5007206
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42282?
CVE-2021-42282 has been assigned a high severity rating due to its potential to allow elevation of privilege in Active Directory.
How do I fix CVE-2021-42282?
To mitigate CVE-2021-42282, you should apply the security updates provided by Microsoft for the affected versions of Windows Server.
Which versions of Windows Server are affected by CVE-2021-42282?
CVE-2021-42282 affects multiple Windows Server versions including 2008, 2012, 2016, 2019, 2022, and specifically the 20H2 update.
What type of vulnerability is CVE-2021-42282?
CVE-2021-42282 is classified as an elevation of privilege vulnerability within Active Directory Domain Services.
Can exploiting CVE-2021-42282 lead to further attacks?
Exploitation of CVE-2021-42282 could allow an attacker to gain higher privileges, potentially leading to broader system compromise.