Microsoft Windows AppContainer是美国微软(Microsoft)公司的一种沙盒机制,用于控制 UWP 应用可以访问或不访问哪些资源。 Microsoft Windows AppContainer存在安全特征问题漏洞。以下产品和版本受到影响:Windows 10 Version 1909 for ARM64-based Systems,Windows 10 Version 21H1 for x64-based Systems,Windows 10 Version 21H1 for
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Windows 10 Version 1809 | 10.0.0 ~ 10.0.17763.2237 |
cpe:2.3:o:microsoft:windows_10_1809:10.0.17763.2237:*:*:*:*:*:x86:*
|
|
| Microsoft | Windows Server 2019 | 10.0.0 ~ 10.0.17763.2237 |
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.2237:*:*:*:*:*:*:*
|
|
| Microsoft | Windows Server 2019 (Server Core installation) | 10.0.0 ~ 10.0.17763.2237 |
cpe:2.3:o:microsoft:windows_server_2019:10.0.17763.2237:*:*:*:*:*:*:*
|
|
| Microsoft | Windows 10 Version 1909 | 10.0.0 ~ 10.0.18363.1854 |
cpe:2.3:o:microsoft:windows_10_1909:10.0.18363.1854:*:*:*:*:*:x86:*
|
|
| Microsoft | Windows 10 Version 21H1 | 10.0.0 ~ 10.0.19043.1288 |
cpe:2.3:o:microsoft:windows_10_21H1:10.0.19043.1288:*:*:*:*:*:x64:*
|
|
| Microsoft | Windows Server 2022 | 10.0.0 ~ 10.0.20348.288 |
cpe:2.3:o:microsoft:windows_server_2022:10.0.20348.288:*:*:*:*:*:*:*
|
|
| Microsoft | Windows 10 Version 2004 | 10.0.0 ~ 10.0.19041.1288 |
cpe:2.3:o:microsoft:windows_10_1809:10.0.19041.1288:*:*:*:*:*:x64:*
|
|
| Microsoft | Windows Server version 2004 | 10.0.0 ~ 10.0.19041.1288 |
cpe:2.3:o:microsoft:windows_server_2004:10.0.19041.1288:*:*:*:*:*:*:*
|
|
| Microsoft | Windows 10 Version 20H2 | 10.0.0 ~ 10.0.19042.1288 |
cpe:2.3:o:microsoft:windows_10_20H2:10.0.19042.1288:*:*:*:*:*:x86:*
|
|
| Microsoft | Windows Server version 20H2 | 10.0.0 ~ 10.0.19042.1288 |
cpe:2.3:o:microsoft:windows_server_20H2:10.0.19042.1288:*:*:*:*:*:*:*
|
|
| Microsoft | Windows 11 version 21H2 | 10.0.0 ~ 10.0.22000.258 |
cpe:2.3:o:microsoft:windows_11_21H2:10.0.22000.258:*:*:*:*:*:x64:*
|
|
| Microsoft | Windows 10 Version 1507 | 10.0.0 ~ 10.0.10240.19086 |
cpe:2.3:o:microsoft:windows_10_1507:10.0.10240.19086:*:*:*:*:*:x86:*
|
|
| Microsoft | Windows 10 Version 1607 | 10.0.0 ~ 10.0.14393.4704 |
cpe:2.3:o:microsoft:windows_10_1607:10.0.14393.4704:*:*:*:*:*:x86:*
|
|
| Microsoft | Windows Server 2016 | 10.0.0 ~ 10.0.14393.4704 |
cpe:2.3:o:microsoft:windows_server_2016:10.0.14393.4704:*:*:*:*:*:*:*
|
|
| Microsoft | Windows Server 2016 (Server Core installation) | 10.0.0 ~ 10.0.14393.4704 |
cpe:2.3:o:microsoft:windows_server_2016:10.0.14393.4704:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability CVE-2021-41338 Security Vulnerability Released: Oct 12, 2021 Assigning CNA: Microsoft MITRE CVE-2021-41338 CVSS:3.1 5.5 / 5.0 Attack Vector Local Attack Complexity Low Privileges Required Low User Interaction None Scope Unchanged Confidentiality High Integrity None Availability None Exploit Code Maturity Proof-of-Concept Remediation Level Official Fix Report Confidence Confirmed Please see Common Vulnerability Scoring System for more information on the definition of these metrics. Exploitability The following table provides an exploitability assessment for this vulnerability at the time of original publication. Yes No Exploitation Less Likely | https://github.com/Mario-Kart-Felix/firewall-cve | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-26427 | 9.0 CRITICAL | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-36970 | 8.8 HIGH | Windows Print Spooler Spoofing Vulnerability |
| CVE-2021-41344 | 8.1 HIGH | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2021-40487 | 8.1 HIGH | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2021-41348 | 8.0 HIGH | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2021-40461 | 8.0 HIGH | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2021-38672 | 8.0 HIGH | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2021-40464 | 8.0 HIGH | Windows Nearby Sharing Elevation of Privilege Vulnerability |
| CVE-2021-40450 | 7.8 HIGH | Win32k Elevation of Privilege Vulnerability |
| CVE-2021-40462 | 7.8 HIGH | Windows Media Foundation Dolby Digital Atmos Decoders Remote Code Execution Vulnerability |
| CVE-2021-40449 | 7.8 HIGH | Win32k Elevation of Privilege Vulnerability |
| CVE-2021-40473 | 7.8 HIGH | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2021-40474 | 7.8 HIGH | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2021-40477 | 7.8 HIGH | Windows Event Tracing Elevation of Privilege Vulnerability |
| CVE-2021-40479 | 7.8 HIGH | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2021-40480 | 7.8 HIGH | Microsoft Office Visio Remote Code Execution Vulnerability |
| CVE-2021-40485 | 7.8 HIGH | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2021-40486 | 7.8 HIGH | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2021-40478 | 7.8 HIGH | Storage Spaces Controller Elevation of Privilege Vulnerability |
| CVE-2021-40467 | 7.8 HIGH | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
Showing top 20 of 71 CVEs. View all on vendor page → →
No comments yet