Lucene search

K
mscveMicrosoftMS:CVE-2021-41363
HistoryOct 12, 2021 - 7:00 a.m.

Intune Management Extension Security Feature Bypass Vulnerability

2021-10-1207:00:00
Microsoft
msrc.microsoft.com
14
intune
management
extension
security
feature
bypass
vulnerability
microsoft

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS3

4.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N

EPSS

0

Percentile

9.5%

Affected configurations

Vulners
Node
microsoftintune_management_extensionRange<1.45.204.0
VendorProductVersionCPE
microsoftintune_management_extension*cpe:2.3:a:microsoft:intune_management_extension:*:*:*:*:*:*:*:*

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS3

4.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N

EPSS

0

Percentile

9.5%

Related for MS:CVE-2021-41363