CVE detail
CVE-2021-42287
Active Directory Domain Services Elevation of Privilege Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.9 · diversity 18.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
11 source links · newest first
- Top 10 ransomware groups to watchCSO Online
The ransomware landscape has seen a lot of fragmentation over the past couple of years with major groups shutting down after they became the target of law enforcement actions or after they attracted too much attention and had ransoms put on their leaders’ identities. Ransomware-as-a-service (RaaS) operations are heavily reliant on third-party hackers, known as […]
newswww.csoonline.comSep 16, 2024, 7:00 AM A ransomware-as-a-service operation known as Black Basta has grown to be one of the most prolific cybercrime threats over the past two years, managing to compromise over 500 organizations from around the world. Many of its victims have been healthcare providers and organizations that operate critical infrastructure, according to the FBI. “Healthcare organizations are attractive […]
newswww.csoonline.comMay 14, 2024, 9:40 PMThe highly active Black Basta ransomware has been linked by cybersecurity firm SentinelOne to the notorious Russian cybercrime group known as FIN7.
newswww.securityweek.comNov 4, 2022, 12:11 PMMicrosoft Active Directory debuted 22 years ago. In computer age, that’s old technology. Threat actors like old technology because it often has legacy code or processes that are not secured to modern standards or organizations have not kept up with patches and recommended settings. Derek Melber, chief technology and security strategist for Tenable, discussed Active […]
newswww.csoonline.comJun 29, 2022, 9:00 AMIf you are as old as I am, you remember when you first had to deal with domains and Active Directory (AD). Even if you aren’t as old as I am, you still probably must deal with domains and Active Directory. If you are just starting out at a new firm, you probably know only […]
newswww.csoonline.comMay 25, 2022, 9:00 AMThe U.S. CISA added the CVE-2022-23176 flaw in WatchGuard Firebox and XTM appliances to its Known Exploited Vulnerabilities Catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the CVE-2022-23176 flaw in WatchGuard Firebox and XTM appliances to its Known Exploited Vulnerabilities Catalog. According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, […]
newssecurityaffairs.comApr 12, 2022, 8:36 AMSeveral years ago I documented Windows updates that needed additional registry keys to be set before you are fully patched. These updates can be hard to keep track of. Microsoft recently released several more updates that need action on your part. The Microsoft Japanese security team documented several updates released in November 2021 that need […]
newswww.csoonline.comJan 5, 2022, 10:00 AMMicrosoft warns of a couple of Active Directory flaws fixed with the November 2021 Patch Tuesday updates that could allow takeover of Windows domains. Microsoft released an alert on a couple of Active Directory vulnerabilities, that have been fixed with the November 2021 Patch Tuesday security updates, that could allow threat actors to takeover Windows domains. The flaws, tracked […]
newssecurityaffairs.comDec 21, 2021, 3:42 PMMicrosoft on Monday released an alert on two Active Directory vulnerabilities addressed with the November 2021 Patch Tuesday updates, urging customers to install the available patches as soon as possible, to prevent potential compromise.
newswww.securityweek.comDec 21, 2021, 1:32 PMNo excerpt available.
Mitigationwww.cisa.govNov 10, 2021, 1:19 AM- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42287portal.msrc.microsoft.com
No excerpt available.
Vendor Advisoryportal.msrc.microsoft.comNov 10, 2021, 1:19 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-20940CVSS 7.8 · High
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-20936CVSS 4.3 · Medium
Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.
- CVE-2026-20931CVSS 8.0 · High
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.
- CVE-2026-20929CVSS 7.5 · High
Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
- CVE-2026-20927CVSS 5.3 · Medium
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network.
- CVE-2026-20925CVSS 6.5 · Medium
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.