CVE-2021-33749High· 8.8▾ TwilightWindows DNS Snap-in Remote Code Execution Vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.2%
2.2% → 2.4%
Windows DNS Snap-in Remote Code Execution Vulnerability
windows_10windows_10 = 20h2windows_10 = 21h1windows_10 = 1809windows_10 = 1909windows_10 = 2004windows_7windows_8.1windows_rt_8.1windows_server_2008windows_server_2008 = r2windows_server_2012windows_server_2012 = r2windows_server_2016windows_server_2016 = 20h2windows_server_2016 = 2004windows_server_2019Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2020-1166High· 7.8An elevation of privilege vulnerability exists when Windows improperly handles calls to Clipboard Service
CVE-2020-1165High· 7.8An elevation of privilege vulnerability exists when Windows improperly handles calls to Clipboard Service
CVE-2020-1164High· 7.0An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory
CVE-2020-1158High· 7.8An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory
CVE-2020-1157High· 7.8An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory
CVE-2020-1156High· 7.8An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory