CVE-2021-42286: Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability
Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19041.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1348Patch KB5007186
Event History
Frequently Asked Questions
What is CVE-2021-42286?
CVE-2021-42286 is a vulnerability in the Windows Core Shell SI Host Extension Framework that allows for the elevation of privilege.
Which versions of Microsoft Windows are affected by CVE-2021-42286?
Microsoft Windows 10 versions 20H2, 21H1, and 2004, as well as Windows Server versions 20H2 and 2016, are affected by CVE-2021-42286.
What is the severity of CVE-2021-42286?
CVE-2021-42286 has a severity rating of 7.8, which is considered high.
How can I fix CVE-2021-42286?
To fix CVE-2021-42286, users should apply the latest security updates from Microsoft.
Where can I find more information about CVE-2021-42286?
More information about CVE-2021-42286 can be found on the Microsoft Security Guidance Advisory page at https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42286.