Record summary

CVE-2021-43226 has a selected CVSS score of 7.8 (high). CISA lists CVE-2021-43226 in KEV; VulnCheck reports CVE-2021-43226 use in known ransomware campaigns.

Description

Windows Common Log File System Driver Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43207.

Description source: GitHub Advisory

Exploitation context

Known exploitation

CISA KEV
Listed · Oct 6, 2025 · CISA
VulnCheck KEV
Listed · Jun 13, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 4, 2025 · Source: CVE List

Affected products and versions

Showing 12 of 28
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE List10.0.0 to < 10.0.10240.19145affected
CVE List10.0.0 to < 10.0.14393.4825affected
CVE List10.0.0 to < 10.0.17763.2366affected
CVE List10.0.0 to < 10.0.18363.1977affected
CVE List10.0.0 to < 10.0.19041.1415affected
CVE List10.0.0 to < 10.0.19042.1415affected
CVE List10.0.0 to < 10.0.19043.1415affected
CVE List10.0.0 to < 10.0.19044.1415affected
CVE List10.0.0 to < 10.0.22000.376affected
CVE List6.1.0 to < 6.1.7601.25796affected
CVE List6.1.0 to < 6.1.7601.25796affected

References

3