CVE-2021-42300 is a tampering vulnerability affecting Microsoft Azure Sphere, allowing a highly privileged local attacker to compromise the integrity of the device. With a CVSS score of 6.7 (Medium), exploitation requires high privileges and local access, but can lead to high impact on confidentiality, integrity, and availability. There is no public exploit code available, nor is it listed in CISA's KEV catalog, indicating it is not actively exploited in the wild. Despite limited community discussion and media coverage, it was addressed in Microsoft's November 2021 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 21.10CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_sphere:*:*:*:*:*:*:*:* | ||
>= 20.00, < 22.07CPE match | cpe:2.3:a:microsoft:azure_sphere:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.