CVE-2021-28313 - CVE House
Back to Database
Status published High CVE-2021-28313

Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability

Affected Vendor

Affected Software

Windows 10 Version 1803, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows Server, version 1909 (Server Core installation), Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8), Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8), Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3), Microsoft Visual Studio 2019 version 16.7 (includes 16.0 – 16.6), Microsoft Visual Studio 2015 Update 3
Vulnerable Versions:
10.0.0, 15.0.0, 15.9.0, 16.0, 16.0.0, 14.0.0

Timeline

Official Publish: April 13th, 2021
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.