← Vulnerability feed

Vulnerability record · CVE-2021-42287 · published 10 November 2021

CVE-2021-42287: Microsoft Active Directory Domain Services privilege escalation

Microsoft · Windows Server 2004

CVE-2021-42287 is an elevation of privilege flaw in Microsoft Active Directory Domain Services affecting multiple Windows Server versions. The record provides only a one-line description and no technical root cause, so the exact mechanism cannot be stated from the supplied facts. It matters because it is listed in CISA KEV with known ransomware use and has a very high EPSS score.

7.5 CVSS 3.1 High CISA KEV since 11 Apr 2022 Known ransomware use EPSS 77% · top 0.5%
7.5CVSS 3.1 base score, v2 6.5
77%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
7Affected product versions listed by NVD
3References
19 Aug 2026Last modified by NVD

Description

Active Directory Domain Services Elevation of Privilege Vulnerability

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityIt is in CISA KEV with known ransomware use and has a very high EPSS probability, despite the limited technical detail in the record.

What it is

CVE-2021-42287 is an elevation of privilege flaw in Microsoft Active Directory Domain Services affecting multiple Windows Server versions. The record provides only a one-line description and no technical root cause, so the exact mechanism cannot be stated from the supplied facts. It matters because it is listed in CISA KEV with known ransomware use and has a very high EPSS score.

Impact

An attacker who already holds low-privileged domain credentials can elevate privileges within Active Directory, potentially reaching domain controller or administrative control. Successful exploitation can enable broader compromise of the domain and support ransomware deployment.

Attack surface

Reachable over the network (AV:N) with low privileges required (PR:L) and no user interaction (UI:N), per the CVSS vector. The high attack complexity (AC:H) indicates conditions must be met for exploitation.

Exploitation

CISA KEV lists it as exploited in the wild since 2022-04-11, with known ransomware campaign use, and EPSS 30-day probability is 0.7717 (99.5th percentile). References are patch and vendor advisory only; no public exploit details are provided in the record.

What to do

  • Apply the Microsoft updates referenced in the MSRC advisory for all affected Windows Server versions.
  • Prioritize patching domain controllers and any server with AD DS role.
  • Follow CISA KEV required action and meet the remediation due date.
  • Audit and restrict low-privileged domain accounts and service accounts that could be used as a foothold.
  • Monitor for known ransomware activity associated with this CVE, including Black Basta.

Detection

  • Monitor AD DS and domain controller logs for anomalous privilege escalation or account changes.
  • Alert on authentication and directory service events consistent with low-privileged accounts gaining elevated rights.
  • Correlate with threat intelligence for Black Basta and other ransomware indicators.
  • Review KEV and vendor advisories for updated detection guidance.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-42287 to the Known Exploited Vulnerabilities catalog on 11 April 2022 as "Microsoft Active Directory Domain Services Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 2 May 2022.

Ransomware crews whose documented playbooks reference this CVE: