CVE-2021-36948High· 7.8▾ Abyssal⚠ Exploited in the wild0dayWindows Update Medic Service Elevation of Privilege Vulnerability
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 42.9 · likelihood 4.7 · exploitation 25
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Nov 17, 2021
Last analysed / modified upstream
27%
Added to the CISA catalog on Nov 3, 2021. Federal remediation due Nov 17, 2021. View catalog ↗
Windows Update Medic Service Elevation of Privilege Vulnerability
windows_10_1809 < 10.0.17763.2114windows_10_1909 < 10.0.18363.1734windows_10_2004 < 10.0.19041.1165windows_10_20h2 < 10.0.19042.1165windows_10_21h1 < 10.0.19043.1165windows_server_2004 < 10.0.19041.1165windows_server_2019 < 10.0.17763.2114windows_server_20h2 < 10.0.19042.1165Upgrade past the affected range:
windows_10_1809 10.0.17763.2114windows_10_1909 10.0.18363.1734windows_10_2004 10.0.19041.1165windows_10_20h2 10.0.19042.1165windows_10_21h1 10.0.19043.1165windows_server_2004 10.0.19041.1165windows_server_2019 10.0.17763.2114windows_server_20h2 10.0.19042.1165Connected by shared product, vendor, weakness, or advisory.
CVE-2022-21882High· 7.0Win32k Elevation of Privilege Vulnerability
CVE-2021-34486High· 7.8Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-36934High· 7.8An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database
CVE-2024-21338High· 7.8Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-85880High· 7.8Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-83991Medium· 5.5Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.