CVE-2021-1663 is an information disclosure vulnerability in the Windows Projected File System (ProjFS) FS Filter Driver, affecting Microsoft Windows 10 and Windows Server 2016. With a CVSS score of 5.5 (Medium), this vulnerability requires local access and low privileges to exploit, potentially leading to high confidentiality impact without affecting integrity or availability. While it has a low EPSS score and is not listed in KEV or the Hot List, it received some community discussion and media coverage at the time of its disclosure. There is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and it is not known to be actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:*:* | ||
2004CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:2004:*:*:*:*:*:*:* | ||
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:20h2:*:*:*:*:*:*:* | ||
2004CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:2004:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.