CVE-2021-36949 is an authentication bypass vulnerability affecting Microsoft Azure Active Directory Connect and its provisioning agent. With a CVSS score of 7.1 (HIGH), this vulnerability allows an attacker on the adjacent network to achieve high confidentiality, integrity, and availability impact with high attack complexity and low privileges. There is currently no public exploit code available, it is not listed in CISA's KEV catalog, and it has garnered limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.3.20.0, <= 1.6.11.3CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_active_directory_connect:*:*:*:*:*:*:*:* | ||
>= 2.0.3.0, <= 2.0.9.0CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_active_directory_connect:*:*:*:*:*:*:*:* | ||
< 1.1.582.0CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_active_directory_connect_provisioning_agent:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.