CVE-2021-40455

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Windows Installer Spoofing Vulnerability

References

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40455

Details

Source: MITRE

Published: 2021-10-13

Updated: 2021-10-19

Risk Information

CVSS v2

Base Score: 2.1

Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10:21h1:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_10:2004:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_10:2004:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_10:2004:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:arm64:*

cpe:2.3:o:microsoft:windows_11:-:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server:20h2:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server:2004:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*

cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*

cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*

cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*

Tenable Plugins

View all (11 total)

IDNameProductFamilySeverity
154043KB5006715: Windows Server 2008 Security Update (October 2021)NessusWindows : Microsoft Bulletins
high
154042KB5006674: Windows 11 Security Update (October 2021)NessusWindows : Microsoft Bulletins
high
154041KB5006675: WWindows 10 version 1507 LTS Security Update (October 2021)NessusWindows : Microsoft Bulletins
high
154040KB5006729: Windows Server 2012 R2 Security Update (October 2021)NessusWindows : Microsoft Bulletins
high
154037KB5006667: Windows 10 version 1909 Security Update (October 2021)NessusWindows : Microsoft Bulletins
high
154036KB5006732: Windows Server 2012 Security Update (October 2021)NessusWindows : Microsoft Bulletins
high
154035KB5006728: Windows 7 and Windows Server 2008 R2 Security Update (October 2021)NessusWindows : Microsoft Bulletins
high
154034KB5006669: Windows 10 Version 1607 and Windows Server 2016 Security Update (October 2021)NessusWindows : Microsoft Bulletins
high
154033KB5006670: Windows 10 Version 2004 / Windows 10 Version 20H2 / Windows 10 Version 21H1 October 2021 Security UpdateNessusWindows : Microsoft Bulletins
high
154029KB5006699: Windows Server 2022 Security Update (October 2021)NessusWindows : Microsoft Bulletins
high
154026KB5006672: Windows 10 Version 1809 and Windows Server 2019 Security Update (October 2021)NessusWindows : Microsoft Bulletins
high