CVE-2021-41363HighCVSS 4.2

Intune Management Extension Security Feature Bypass Vulnerability

Published
October 12, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Are there any pre-requisites for this vulnerability to be exploited in Intune Management Extension? This vulnerability only exists when Intune Management Extension is enabled as managed installer. Enabling IME as managed installer requires local administrator privileges. What should I do to protect myself from this vulnerability? No action is required. As soon as the client connects to the service, it automatically receives a message to update.

🎯 Affected products1

  • Intune management extension

✅ Remediation

KBWhat's New? (Security Update) — fixed build 1.45.204.0

🔗 References (1)