Vulnerability record · CVE-2021-42278 · published 10 November 2021
CVE-2021-42278: Microsoft Active Directory Domain Services privilege escalation
Microsoft · Windows Server 2004
CVE-2021-42278 is an elevation of privilege flaw in Microsoft Active Directory Domain Services affecting multiple Windows Server versions. The record gives only a one-line description and no root-cause detail, but the flaw is remotely reachable by a low-privileged authenticated user and has been exploited in ransomware campaigns, so it matters for any environment with AD domain controllers.
Description
Active Directory Domain Services Elevation of Privilege Vulnerability
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use, has very high EPSS, and enables domain-wide privilege escalation.
What it is
CVE-2021-42278 is an elevation of privilege flaw in Microsoft Active Directory Domain Services affecting multiple Windows Server versions. The record gives only a one-line description and no root-cause detail, but the flaw is remotely reachable by a low-privileged authenticated user and has been exploited in ransomware campaigns, so it matters for any environment with AD domain controllers.
Impact
An attacker with a low-privileged domain account can elevate privileges, potentially to domain administrator level, gaining control over the directory and the systems that trust it.
Attack surface
Reached over the network (AV:N) by an attacker who holds low privileges (PR:L); no user interaction is required (UI:N). The specific protocol or interface is not described in the record.
Exploitation
Listed in CISA KEV since 2022-04-11 with known ransomware campaign use, and EPSS 30-day probability is about 0.733 (99.4th percentile), indicating active, widespread exploitation.
What to do
- Apply the Microsoft updates referenced in the MSRC advisory for all affected Windows Server versions.
- Treat domain controllers as high-value assets and restrict which accounts can create or modify computer accounts.
- Audit and remove unnecessary machine account creation rights from non-administrative users.
- Monitor for and remediate the related sAMAccountName spoofing behavior associated with this class of attack.
- Prioritize patching of domain controllers and any server with AD DS role.
Detection
- Monitor for anomalous machine account creation or sAMAccountName changes, especially clearing the trailing $ on computer accounts.
- Alert on Kerberos ticket requests or authentication events involving newly created or renamed computer accounts.
- Correlate low-privileged account activity with subsequent privileged access or domain controller authentication.
- Review domain controller security logs for unusual account modification patterns outside change windows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-42278 to the Known Exploited Vulnerabilities catalog on 11 April 2022 as "Microsoft Active Directory Domain Services Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 2 May 2022.
Ransomware crews whose documented playbooks reference this CVE: