- Description
- Windows Update Medic Service Elevation of Privilege Vulnerability
- Source
- secure@microsoft.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 4.6
- Impact score
- 6.4
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:P/A:P
Data from CISA
- Vulnerability name
- Microsoft Windows Update Medic Service Privilege Escalation Vulnerability
- Exploit added on
- Nov 3, 2021
- Exploit action due
- Nov 17, 2021
- Required action
- Apply updates per vendor instructions.
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F8D40D82-1D88-4CF1-B961-F9F28426C56B",
"versionEndExcluding": "10.0.17763.2114"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1909:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3DD2BDE6-67C6-48E2-BED0-12E4CC7EE6BC",
"versionEndExcluding": "10.0.18363.1734"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_2004:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "70336A6A-DE45-4604-BE81-10DA4DF12D3F",
"versionEndExcluding": "10.0.19041.1165"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_20h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7AB7321A-1F89-48B3-8E5A-94791AB2BC86",
"versionEndExcluding": "10.0.19042.1165"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h1:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A860F2B-0533-46F7-879E-B932E4E44F0D",
"versionEndExcluding": "10.0.19043.1165"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2004:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C90BEC5F-E0A8-43C5-BB0D-251D19BFD66B",
"versionEndExcluding": "10.0.19041.1165"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "61219C24-A1AE-427F-BBF8-A984BCB1CA6F",
"versionEndExcluding": "10.0.17763.2114"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_20h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "45A85E4C-6C7A-4B72-832D-AC12A78565C3",
"versionEndExcluding": "10.0.19042.1165"
}
],
"operator": "OR"
}
]
}
]