CVE-2021-42278🔥 Known Exploited (CISA KEV)HIGH7.5CVSS Severity ScoreEPSS Score91.7120%EPSS Percentile91.67thPublished2021-11-10Last Modified2025-10-30Data SourcesNVDCISA KEVFIRST.org EPSSVulnerability DescriptionActive Directory Domain Services Elevation of Privilege VulnerabilityAffected Platforms (CPE)💻MicrosoftWindows Server 2004< 10.0.19041.1348💻MicrosoftWindows Server 2008All versions= r2💻MicrosoftWindows Server 2012All versions= r2💻MicrosoftWindows Server 2016< 10.0.14393.4770Show All Affected Platforms (+3 more)References & Advisories🔗 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42278🔗 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42278🔗 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-42278