CVE-2021-42278High· 7.5▾ Abyssal⚠ Exploited in the wildPoC availableActive Directory Domain Services Elevation of Privilege Vulnerability
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 41.3 · likelihood 14.7 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due May 2, 2022
Last analysed / modified upstream
70%
70% → 73%
6 GitHub repos
Added to the CISA catalog on Apr 11, 2022. Federal remediation due May 2, 2022. View catalog ↗
Active Directory Domain Services Elevation of Privilege Vulnerability
windows_server_2004 < 10.0.19041.1348windows_server_2008windows_server_2008 = r2windows_server_2012windows_server_2012 = r2windows_server_2016 < 10.0.14393.4770windows_server_2019 < 10.0.17763.2300windows_server_2022 < 10.0.20348.350windows_server_20h2 < 10.0.19042.1348Upgrade past the affected range:
windows_server_2004 10.0.19041.1348windows_server_2016 10.0.14393.4770windows_server_2019 10.0.17763.2300windows_server_2022 10.0.20348.350windows_server_20h2 10.0.19042.1348Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-36942High· 7.5Windows LSA Spoofing Vulnerability
CVE-2026-85880High· 7.8Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-81963High· 7.8Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVE-2026-83991Medium· 5.5Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.
CVE-2026-88097High· 8.1Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
CVE-2026-62874Critical· 10.0Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.