← Threat Center
8.8
HIGH • CVSS 3.1

CVE-2021-42287

CISA KNOWN EXPLOITED

Active Directory Domain Services Elevation of Privilege Vulnerability

Prioritization

NVD CVSS
8.8
Published
Nov 9, 2021 8:19 PM EST
Modified
Aug 19, 2026 3:23 PM EDT
CISA KEV
Yes
KEV due date
2022-05-02
CISA required action

Apply updates per vendor instructions.

Red Hat context

No Red Hat-specific cached context is available for this record.

DEFENSIVE REMEDIATION WORKFLOW

Recommended response

  1. Treat as priority because it appears in CISA Known Exploited Vulnerabilities data; follow the required action and due date where applicable.
  2. Identify affected assets with Qualys, Tanium, software inventory, CMDB or configuration-management data.
  3. Confirm package/application applicability before change execution; CVSS alone does not prove that every host is vulnerable.
  4. Patch, upgrade, rehydrate or apply a vendor-approved mitigation through controlled change. GraceITS can automate eligible waves with Ansible/Tanium.
  5. Rescan after remediation and reconcile remaining exceptions, false positives, unsupported systems and compensating controls.