CVE-2021-42301 describes an information disclosure vulnerability within Microsoft Azure RTOS. This medium-severity flaw (CVSS 4.6) has a physical attack vector and low attack complexity, potentially leading to high confidentiality impact without affecting integrity or availability. While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it received limited community discussion and media coverage, notably being addressed in Microsoft's November 2021 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.1.9CPE matchmatch criteria | cpe:2.3:o:microsoft:azure_rtos:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.1.9CPE match | cpe:2.3:a:microsoft:azure_real_time_operating_system:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.