CVE-2021-28324

HIGH EXPLOITED

Windows 10 and Windows Server 2016 - Information Disclosure via SMB

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-28324 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

Windows SMB Information Disclosure Vulnerability

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0622
EPSS Percentile 92.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2021-08-17
Status published
Products (4)
microsoft/windows_10 20h2
microsoft/windows_10 2004
microsoft/windows_server_2016 20h2
microsoft/windows_server_2016 2004
Published Apr 13, 2021
Tracked Since Feb 18, 2026