Permissions, Privileges, and Access Controls in Microsoft Windows and Windows Server - CVE-2021-31958
Published: June 8, 2021
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in the Windows NTLM. A remote attacker can trick a victim to visit a specially crafted server share or website, which leads to security restrictions bypass and privilege escalation.
Affected software
Windows Server
Dell EMC VNXe3200
Solutions Enabler Virtual Appliance
Solutions Enabler
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
How to mitigate CVE-2021-31958
Solutions Enabler Virtual Appliance - addressed in versions 9.1.0.17, 9.2.2.0
Solutions Enabler - addressed in versions 9.1.0.17, 9.2.2.0
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.1.0.28, 9.2.2.2
Unisphere for PowerMax - addressed in versions 9.1.0.28, 9.2.2.2