CVE-2021-26898

Summary

Windows Event Tracing Elevation of Privilege Vulnerability

Affected Software

VendorProductVersion RangeStatus
MicrosoftWindows 10 Version 150710.0.10240.0 < 10.0.10240.18874affected
MicrosoftWindows 10 Version 160710.0.14393.0 < 10.0.14393.4283affected
MicrosoftWindows 10 Version 180310.0.0 < 10.0.17134.2087affected
MicrosoftWindows 10 Version 180910.0.17763.0 < 10.0.17763.1817affected
MicrosoftWindows 10 Version 180910.0.0 < 10.0.17763.1817affected
MicrosoftWindows 10 Version 190910.0.0 < 10.0.18363.1440affected
MicrosoftWindows 10 Version 200410.0.0 < 10.0.19043.867affected
MicrosoftWindows 10 Version 20H210.0.0 < 10.0.19043.867affected
MicrosoftWindows 76.1.0 < 6.1.7601.24566affected
MicrosoftWindows 7 Service Pack 16.1.0 < 6.1.7601.24566affected
MicrosoftWindows 8.16.3.0 < 6.3.9600.19968affected
MicrosoftWindows Server 2008 R2 Service Pack 16.1.7601.0 < 6.1.7601.24566affected
MicrosoftWindows Server 2008 R2 Service Pack 1 (Server Core installation)6.1.7601.0 < 6.1.7601.24566affected
MicrosoftWindows Server 2008 Service Pack 26.0.6003.0 < 6.0.6003.21070affected
MicrosoftWindows Server 2008 Service Pack 2 (Server Core installation)6.0.6003.0 < 6.0.6003.21070affected
MicrosoftWindows Server 20126.2.9200.0 < 6.2.9200.23298affected
MicrosoftWindows Server 2012 (Server Core installation)6.2.9200.0 < 6.2.9200.23298affected
MicrosoftWindows Server 2012 R26.3.9600.0 < 6.3.9600.19968affected
MicrosoftWindows Server 2012 R2 (Server Core installation)6.3.9600.0 < 6.3.9600.19968affected
MicrosoftWindows Server 201610.0.14393.0 < 10.0.14393.4283affected
MicrosoftWindows Server 2016 (Server Core installation)10.0.14393.0 < 10.0.14393.4283affected
MicrosoftWindows Server 201910.0.17763.0 < 10.0.17763.1817affected
MicrosoftWindows Server 2019 (Server Core installation)10.0.17763.0 < 10.0.17763.1817affected
MicrosoftWindows Server version 200410.0.0 < 10.0.19043.867affected
MicrosoftWindows Server version 20H210.0.0 < 10.0.19043.867affected
MicrosoftWindows Server, version 1909 (Server Core installation)10.0.0 < 10.0.18363.1440affected

Weaknesses

  • Elevation of Privilege

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References