CVE detail
CVE-2021-36942
Windows LSA Spoofing Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.9 · diversity 19.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
11 source links · newest first
A new type of authentication coercion attack exploits an obscure and rarely monitored remote procedure call (RPC) interface.
vendorunit42.paloaltonetworks.comNov 11, 2025, 4:30 AMChina-based threat actors exploited ToolShell SharePoint flaw CVE-2025-53770 soon after its July patch. China-linked threat actors exploited the ToolShell SharePoint flaw vulnerability, tracked as CVE-2025-53770, to breach a telecommunications company in the Middle East after it was addressed by Microsoft in July 2025. “China-based attackers used the ToolShell vulnerability (CVE-2025-53770) to compromise a telecoms company in […]
newssecurityaffairs.comOct 24, 2025, 8:37 AM- Ridding your network of NTLMCSO Online
Microsoft has hinted at a possible end to NTLM a few times, but with quite a few Windows 95 or 98 in use that do not support the alternative, Kerberos, it won’t be an easy job to do. There is the option to disable NTLM when using Azure Active Directory but that may not always […]
newswww.csoonline.comJan 20, 2025, 7:00 AM Since introducing NTLM coercion techniques such as PetitPotam into the NodeZero platform, we frequently have security practitioners request help understanding these techniques and what impact they have to their enterprise. There is a lack of concise resources to inform Blue Teams on how these techniques work, and clearly distinguishing them from other misconfigurations/vulnerabilities in the […]
exploithorizon3.aiJan 9, 2024, 3:47 PM- In 2022, more than 40% of zero-day exploits used in the wild were variations of previous issuesSecurity Affairs
Google’s Threat Analysis Group Google states that more than 40% of zero-day flaws discovered in 2022 were variants of previous issues. The popular Threat Analysis Group (TAG) Maddie Stone wrote Google’s fourth annual year-in-review of zero-day flaws exploited in-the-wild [2021, 2020, 2019], it is built off of the mid-year 2022 review. In 2022, the researchers […]
newssecurityaffairs.comJul 30, 2023, 4:38 PM - Half of actively exploited zero-day issues in H1 2022 are variants of previous flawsSecurity Affairs
Google Project Zero states that in H1 2022 at least half of zero-day issues exploited in attacks were related to not properly fixed old flaws. Google Project Zero researcher Maddie Stone published a blog post that resumes her speech at the FIRST conference in June 2022, the presentation is titled “0-day In-the-Wild Exploitation in 2022…so […]
newssecurityaffairs.comJul 3, 2022, 1:31 PM The US Cybersecurity and Infrastructure Security Agency (CISA) has temporarily removed a Windows flaw from its Known Exploited Vulnerabilities Catalog after it was informed by Microsoft that a recent update can cause problems on some types of systems.
newswww.securityweek.comMay 16, 2022, 11:16 AMMicrosoft software products are a connective tissue of many organizations, from online documents (creating, sharing, storing), to email and calendaring, to the operating systems that enable business operations on the front and back ends, both in the cloud and on premises. Over 1 million companies worldwide and over 731,000 companies in the U.S. use Office 365, and though Microsoft offers no hard stats, some sources suggest there are over 90,000 Microsoft partners facilitating services and … More →
newswww.helpnetsecurity.comDec 10, 2021, 6:30 AMThe recently disclosed Windows Server vulnerability dubbed “PetitPotam” is being actively exploited in malicious attacks, including some aimed at deploying a piece of ransomware named LockFile.
newswww.securityweek.comAug 23, 2021, 12:20 PMSlovenia-based ACROS Security this week announced the release of patches that address additional attack vectors for the PetitPotam vulnerability.
newswww.securityweek.comAug 20, 2021, 11:19 AM- Microsoft patches actively exploited zero-day (CVE-2021-36948), more Print Spooler flawsHelp Net Security
Microsoft’s August 2021 Patch Tuesday is pretty lightweight, through it covers a wide variety of Microsoft solutions. 44 CVE-numbered security holes have been plugged, seven of which are critical, and one is actively exploited (CVE-2021-36948). Fixed vulnerabilities of note Let’s start with the zero-day. CVE-2021-36948 is a vulnerability in the Windows Update Medic Service that can be exploited by attackers to escalate privileges on a compromised system (and misuse them to do things like create … More →
newswww.helpnetsecurity.comAug 10, 2021, 8:26 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2021-43226CVSS 7.8 · High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
KEV listed3 mentions - CVE-2021-42278CVSS 7.5 · High
Active Directory Domain Services Elevation of Privilege Vulnerability
KEV listed9 mentions - CVE-2021-41379CVSS 5.5 · Medium
Windows Installer Elevation of Privilege Vulnerability
- CVE-2021-40449CVSS 7.8 · High
Win32k Elevation of Privilege Vulnerability
- CVE-2021-40444CVSS 8.8 · High
<p>Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exp…
- CVE-2021-36955CVSS 7.8 · High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
KEV listed1 mention