CVE-2021-33779 is a high-severity security feature bypass vulnerability affecting Microsoft Windows Server 2016 and 2019's Active Directory Federation Services (AD FS). With a CVSS score of 8.1, it allows a low-privileged attacker to achieve high confidentiality and integrity impacts over the network without user interaction. While there is no public exploit code (Metasploit, Nuclei, ExploitDB) and it's not listed in CISA's KEV catalog, the vulnerability has garnered significant community discussion and media coverage, indicating notable attention from security researchers. Microsoft has released patches to address this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* | ||
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:20h2:*:*:*:*:*:*:* | ||
2004CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:2004:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.