CVE-2021-42287
Active Directory Domain Services Elevation of Privilege Vulnerability
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Apr 11, 2022
- US federal agencies must remediate it by May 2, 2022 (BOD 22-01)
- First attack observed 152 days after disclosure
- Confirmed by sensors, not only by reports
- Used in ransomware campaigns
Apply updates per vendor instructions.
Source: CISA KEV · Sep 9, 2026 Mar 25, 2026 Sep 12, 2025 Apr 28, 2025 Mar 12, 2025 Sep 19, 2024
CVSS score7.5 / 10
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HVendorsmicrosoft
Affected products
| Vendors | Product | Versions |
|---|---|---|
| microsoft | windows server 2008 | - |
| microsoft | windows server 2012 | - |
| microsoft | windows server 2016 | < 10.0.14393.4770 |
| microsoft | windows server 2019 | < 10.0.17763.2300 |
| microsoft | windows server 2022 | < 10.0.20348.350 |
| microsoft | windows server 2004 | < 10.0.19041.1348 |
| microsoft | windows server 20h2 | < 10.0.19042.1348 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
