4.6
CVSSv2

CVE-2021-43238

Published: 15/12/2021 Updated: 12/07/2022
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

This vulnerability allows local malicious users to create a denial-of-service condition on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Remote Access Connection Manager service. By creating a directory junction, an attacker can abuse the service to create a directory. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 10 -

microsoft windows 10 1607

microsoft windows server 2008 r2

microsoft windows 7 -

microsoft windows server 2012 r2

microsoft windows server 2016 -

microsoft windows server 2008 -

microsoft windows 10 20h2

microsoft windows 10 1809

microsoft windows 10 1909

microsoft windows 10 2004

microsoft windows 8.1 -

microsoft windows rt 8.1 -

microsoft windows server 2016 2004

microsoft windows server 2012 -

microsoft windows server 2019 -

microsoft windows 10 21h1

microsoft windows 10 21h2

microsoft windows 11 -

microsoft windows server 20h2

microsoft windows server 2022