CVE-2021-38624HighCVSS 6.5
Windows Key Storage Provider Security Feature Bypass Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What kind of security feature could be bypassed by successfully exploiting this vulnerability? A successful attacker could bypass the Windows Key Storage Provider which issues key certificates for trust in attestation scenarios.
🎯 Affected products22
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1909 for 32-bit Systems
- Windows 10 Version 1909 for ARM64-based Systems
- Windows 10 Version 1909 for x64-based Systems
- Windows 10 Version 2004 for 32-bit Systems
- Windows 10 Version 2004 for ARM64-based Systems
- Windows 10 Version 2004 for x64-based Systems
- Windows 10 Version 20H2 for 32-bit Systems
- Windows 10 Version 20H2 for ARM64-based Systems
- Windows 10 Version 21H1 for 32-bit Systems
- Windows 10 Version 21H1 for ARM64-based Systems
- Windows 10 Version 21H1 for x64-based Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
- Windows Server, version 2004 (Server Core installation)
- Windows Server, version 20H2 (Server Core Installation)
✅ Remediation
KB5006672 (Security Update) — fixed build 10.0.17763.2237 KB5006667 (Security Update) — fixed build 10.0.18363.1854 KB5006670 (Security Update) — fixed build 10.0.19043.1288 KB5006699 (Security Update) — fixed build 10.0.20348.288 KB5006670 (Security Update) — fixed build 10.0.19041.1288 KB5006670 (Security Update) — fixed build 10.0.19042.1288 KB5006674 (Security Update) — fixed build 10.0.22000.258
🔗 References (11)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38624
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5006672
- referencehttps://support.microsoft.com/help/5006672
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5006667
- referencehttps://support.microsoft.com/help/5006667
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5006670
- referencehttps://support.microsoft.com/help/5006670
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5006699
- referencehttps://support.microsoft.com/help/5006699
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5006674
- referencehttps://support.microsoft.com/help/5006674