CVE-2021-43226General(microsoft / windows_10_1507)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft windows_10_1507 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Windows Common Log File System Driver Elevation of Privilege Vulnerability

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-10-27. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_1909

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-13); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_1909windows_10_2004windows_10_20h2windows_10_21h1windows_10_21h2windows_11_21h2windows_7

2 versions affected across 19 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-13: 1Mentions · 2026-08-22: 1Active Exploitation · 2026-08-22: 104-1308-22
Signal classification2 categories
General
150.0%
Active Exploitation
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-131
General1
2026-08-221
Active Exploitation1
Full discourse2 posts
  • kokumօtօ@__kokumoto
    Active Exploitation

    米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性カタログが更新。以下脆弱性について悪用が確認された。 - CVE-2021-43226 (Windows) - CVE-2020-5135 (SonicOS) - CVE-2012-0158 (Windows) https://t.co/36dA3GHlV2

    Post summary

    CISA reports that CVE-2021-43226, CVE-2020-5135, and CVE-2012-0158 have been actively exploited, with no additional exploitation details or mitigations provided.

    00000725
    7.7K followersView on X
  • DailyCVE@dailycve
    General

    🔴 #Windows, Elevation of Privilege, #CVE-2021-43226 (High) https://dailycve.com/windows-elevation-of-privilege-cve-2021-43226-high/

    Post summary

    A link to a CVE summary is posted; no further details or claims about exploitation, patches, or technical aspects are included.

    0000018
    181 followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507--x64
OSmicrosoftwindows_10_1507--x86
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_1909---
OSmicrosoftwindows_10_2004---
OSmicrosoftwindows_10_20h2--arm64
OSmicrosoftwindows_10_20h2--x86
OSmicrosoftwindows_10_21h1---
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_11_21h2---
OSmicrosoftwindows_7---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2004---
OSmicrosoftwindows_server_2008--x64
OSmicrosoftwindows_server_2008--x86
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_20h2---

Explore more