Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2021-33757

Опубликовано: 13 июл. 2021
Источник: msrc
CVSS3: 5.3
EPSS Низкий

Описание

Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability

FAQ

How do the security updates released on July 13, 2021 provide protections for CVE-2021-33757?

After the security updates released on July 13, 2021 or later are installed, Advanced Encryption Standard (AES) encryption will be the preferred method when using the MS-SAMR protocol to change or set account passwords on Windows clients if AES encryption is supported by the SAM server. Please see [KB5004605: Update adds AES encryption protections for CVE-2021-33757[(https://support.microsoft.com/help/5004605) for the following information:

  • Changes made by this update
  • How does this new behavior work?
  • Event logging
  • Registry settings
  • FAQ

Обновления

ПродуктСтатьяОбновление
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2012
Windows Server 2012 (Server Core installation)

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 76%
0.01001
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
почти 4 года назад

Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability

CVSS3: 5.3
github
около 3 лет назад

Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability

CVSS3: 9.8
fstec
почти 4 года назад

Уязвимость диспетчера учётных записей безопасности (Security Account Manager) операционной системы Microsoft Windows, позволяющая нарушителю обойти процесс аутентификации

EPSS

Процентиль: 76%
0.01001
Низкий

5.3 Medium

CVSS3