Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2021-43217

Опубликовано: 14 дек. 2021
Источник: msrc
CVSS3: 8.1
EPSS Средний

Описание

Windows Encrypting File System (EFS) Remote Code Execution Vulnerability

FAQ

What is the attack vector for this vulnerability?

An attacker could cause a buffer overflow write leading to unauthenticated non-sandboxed code execution.

Does EFS need to be in use for this to be exploited?

No. EFS interfaces trigger a start to the EFS service if it isn’t already running.

How does Microsoft plan to address this vulnerability?

Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how EFS makes connections from client to server.

For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see KB5009763: EFS security hardening changes in CVE-2021-43217.

When the second phase of Windows updates become available in Q1 2022, customers will be notified via a revision to this security vulnerability. If you wish to be notified when these updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this advisory. See Microsoft Technical Security Notifications.

How do the two deployment phases address the vulnerability?

The initial deployment phase starts with the Windows updates released on December 14, 2021. The updates will enable packet-level privacy for EFS when the client initiates a connection, and the server will only allow connections with packet-level privacy.

The second phase, planned for a Q1 2022 release, marks the transition into the enforcement phase. Support for the AllowAllCliAuth registry key will be removed and servers will require packet-level privacy regardless of the registry key setting.

Is there a recommended order in which I should install these updates on client and server machines?

Yes. We recommend that you install the security updates to address this vulnerability on client machines first and then on servers.

Обновления

ПродуктСтатьяОбновление
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2012
Windows Server 2012 (Server Core installation)

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 95%
0.20568
Средний

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
больше 3 лет назад

Windows Encrypting File System (EFS) Remote Code Execution Vulnerability

CVSS3: 9.8
github
больше 3 лет назад

Windows Encrypting File System (EFS) Remote Code Execution Vulnerability

CVSS3: 9.8
fstec
больше 3 лет назад

Уязвимость файловой системы шифрования Encrypting File System (EFS) операционной системы Microsoft Windows, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 95%
0.20568
Средний

8.1 High

CVSS3