NVD disclosure day

Published threat advisories for August 12, 2021

CVE advisoryKnown Exploit

CVE-2021-36948

Windows Update Service Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Windows Update Medic Service could allow a local attacker to gain elevated privileges. This could result in unauthorized system control, impacting data integrity and confidentiality. Attackers with local access can exploit this flaw to execute arbitrary code, posing a risk to affected organizatio

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-36942

Windows LSA Spoofing Vulnerability Affects Server Systems

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Windows Server systems are affected by a spoofing vulnerability. Attackers can impersonate services, leading to unauthorized data access and potential business disruption. Organizations should apply vendor updates to mitigate this risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-34486

Microsoft Windows Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Windows Event Tracing allows an attacker with local access to elevate privileges, potentially impacting system integrity and confidentiality. Organizations should identify affected systems and apply vendor updates to mitigate risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-34484

Windows User Profile Service Elevation of Privilege Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Windows User Profile Service can allow an attacker with local access to gain elevated privileges. This could lead to unauthorized access and modification of data, disrupting operations. The risk to organizations includes potential data breaches and system compromise.

• CISA KEV