CVE-2021-38666
HIGHWindows Remote Desktop Client - Remote Code Execution
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-38666. PoCs published by DarkSprings.
AI-analyzed exploit summary The repository contains no exploit code or technical details, only a vague message about identity verification and approval. This is characteristic of a social engineering lure.
Description
Remote Desktop Client Remote Code Execution Vulnerability
Exploits (1)
nomisec
SUSPICIOUS
2 stars
by DarkSprings · poc
https://github.com/DarkSprings/CVE-2021-38666-poc
The repository contains no exploit code or technical details, only a vague message about identity verification and approval. This is characteristic of a social engineering lure.
Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target:
unknown
No auth needed
devstral-2 · analyzed Feb 18, 2026
Full analysis →
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38666
Scores
CVSS v3
8.8
EPSS
0.1299
EPSS Percentile
95.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
Status
published
Products (20)
microsoft/windows_10
microsoft/windows_10
20h2
microsoft/windows_10
21h1
microsoft/windows_10
1607
microsoft/windows_10
1809
microsoft/windows_10
1909
microsoft/windows_10
2004
microsoft/windows_11
(2 CPE variants)
microsoft/windows_7
microsoft/windows_8.1
... and 10 more
Published
Nov 10, 2021
Tracked Since
Feb 18, 2026