CVE-2021-1685 is an Elevation of Privilege vulnerability in Windows AppX Deployment Extensions affecting Microsoft Windows 10, Windows Server 2016, and Windows Server 2019. With a CVSS score of 7.8 (High), this vulnerability allows a local attacker with low privileges to achieve high impact on confidentiality, integrity, and availability without user interaction. There is no evidence of active exploitation, nor are there publicly available exploit modules in common frameworks like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, with only one article mentioning it as part of a larger patch Tuesday update.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:* | ||
1809CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.