Vulnerability record · CVE-2021-42287 · published 10 November 2021
CVE-2021-42287: Microsoft Active Directory Domain Services privilege escalation
Microsoft · Windows Server 2004
CVE-2021-42287 is an elevation of privilege flaw in Microsoft Active Directory Domain Services affecting multiple Windows Server versions. The record provides only a one-line description and no technical root cause, so the exact mechanism cannot be stated from the supplied facts. It matters because it is listed in CISA KEV with known ransomware use and has a very high EPSS score.
Description
Active Directory Domain Services Elevation of Privilege Vulnerability
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use and has a very high EPSS probability, despite the limited technical detail in the record.
What it is
CVE-2021-42287 is an elevation of privilege flaw in Microsoft Active Directory Domain Services affecting multiple Windows Server versions. The record provides only a one-line description and no technical root cause, so the exact mechanism cannot be stated from the supplied facts. It matters because it is listed in CISA KEV with known ransomware use and has a very high EPSS score.
Impact
An attacker who already holds low-privileged domain credentials can elevate privileges within Active Directory, potentially reaching domain controller or administrative control. Successful exploitation can enable broader compromise of the domain and support ransomware deployment.
Attack surface
Reachable over the network (AV:N) with low privileges required (PR:L) and no user interaction (UI:N), per the CVSS vector. The high attack complexity (AC:H) indicates conditions must be met for exploitation.
Exploitation
CISA KEV lists it as exploited in the wild since 2022-04-11, with known ransomware campaign use, and EPSS 30-day probability is 0.7717 (99.5th percentile). References are patch and vendor advisory only; no public exploit details are provided in the record.
What to do
- Apply the Microsoft updates referenced in the MSRC advisory for all affected Windows Server versions.
- Prioritize patching domain controllers and any server with AD DS role.
- Follow CISA KEV required action and meet the remediation due date.
- Audit and restrict low-privileged domain accounts and service accounts that could be used as a foothold.
- Monitor for known ransomware activity associated with this CVE, including Black Basta.
Detection
- Monitor AD DS and domain controller logs for anomalous privilege escalation or account changes.
- Alert on authentication and directory service events consistent with low-privileged accounts gaining elevated rights.
- Correlate with threat intelligence for Black Basta and other ransomware indicators.
- Review KEV and vendor advisories for updated detection guidance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-42287 to the Known Exploited Vulnerabilities catalog on 11 April 2022 as "Microsoft Active Directory Domain Services Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 2 May 2022.
Ransomware crews whose documented playbooks reference this CVE: