CVE-2021-34486: Windows Event Tracing Elevation of Privilege Vulnerability
Overview
- Severity
- High (CVSS 7.8)
- CVSS Vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Elevation of Privilege
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2021-Aug
- Released
- 2021-08-10
- Last Updated
- 2021-08-12
- EPSS Score
- 34.37% (percentile: 97.0%)
- CISA KEV
- Listed — due 2022-04-18
Known Exploits (1)
- Microsoft Windows Event Tracing Privilege Escalation Vulnerability — added 2021-10-12T03:50:44Z
Detection & Weaponization (1 sources)
Maturity: Exploit
- GitHub PoC: 2 repositories
Affected Products (19)
Other
- 11568
- 11569
- 11570
- 11571
- 11572
- 11712
- 11713
- 11714
- 11896
- 11897
- 11898
- 11766
- 11767
- 11768
- 11769
- 11800
- 11801
- 11802
- 11803
Security Updates (3)
Acknowledgments
Yong Chuan Koh (<a href="https://twitter.com/yongchuank">@yongchuank</a>)
Revision History
- 2021-08-10: Information published.
- 2021-08-12: Updated information to include CVSS scores. This is an informational change only.