CVE-2021-1733: Sysinternals PsExec Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 7.8)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Publicly Disclosed
Yes
Patch Tuesday
2021-Feb
Released
2021-02-09
EPSS Score
0.32% (percentile: 55.3%)

FAQ

What version of PSExec contains the update to resolve this vulnerability? PsExec v2.32 is not longer affected by this vulneratiblity.

Affected Products (1)

Developer Tools

  • PsExec

Security Updates (1)

Acknowledgments

David Wells (<a href="https://twitter.com/CE2Wells">@CE2Wells</a>) of Tenable

Revision History

  • 2021-02-09: Information published.