← Back to browse · API

CVE-2021-36942

Severity
HIGH
CVSS
7.5
EPSS
0.66023
Risk score
78.11
CISA KEV
Yes
PoC
No
Published
2021-11-03
Modified
2021-11-03
First seen
2026-08-07
Aliases
EUVD-2021-23518, GHSA-P8QF-GCXQ-47XM
Products
Microsoft:Windows, Microsoft:Windows Server 2008 Service Pack 2 6.0.0 <6.0.6003.21192, Microsoft:Windows Server 2008 R2 Service Pack 1 (Server Core installation) 6.0.0 <6.1.7601.25685, Microsoft:Windows Server 2008 R2 Service Pack 1 6.1.0 <6.1.7601.25685, Microsoft:Windows Server 2008 Service Pack 2 (Server Core installation) 6.0.0 <6.0.6003.21192, Microsoft:Windows Server 2008 Service Pack 2 6.0.0 <6.0.6003.21192, Microsoft:Windows Server 2012 (Server Core installation) 6.2.0 <6.2.9200.23435, Microsoft:Windows Server 2012 6.2.0 <6.2.9200.23435, Microsoft:Windows Server 2012 R2 (Server Core installation) 6.3.0 <6.3.9600.20094, Microsoft:Windows Server 2012 R2 6.3.0 <6.3.9600.20094, Microsoft:Windows Server 2016 (Server Core installation) 10.0.0 <10.0.14393.4583, Microsoft:Windows Server 2016 10.0.0 <10.0.14393.4583, Microsoft:Windows Server 2019 (Server Core installation) 10.0.0 <10.0.17763.2114, Microsoft:Windows Server 2019 10.0.0 <10.0.17763.2114, Microsoft:Windows Server version 2004 10.0.0 <10.0.19041.1165, Microsoft:Windows Server version 20H2 10.0.0 <10.0.19042.1165
Sources
euvd EUVD-2021-23518
cisa.gov CVE-2021-36942

Description

Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM.

References