PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-42278 Microsoft CVE debrief

CVE-2021-42278 is a Microsoft Active Directory Domain Services privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-04-11. Because it is listed in KEV and marked as having known ransomware campaign use, defenders should treat it as a high-priority patching item for Active Directory environments.

Vendor
Microsoft
Product
Active Directory
CVSS
HIGH 7.5
CISA KEV
Listed
Original CVE published
2022-04-11
Original CVE updated
2022-04-11
Advisory published
2022-04-11
Advisory updated
2022-04-11

Who should care

Windows domain administrators, Active Directory and identity platform teams, SOC and vulnerability management teams, and any organization that relies on Microsoft Active Directory Domain Services—especially where domain controllers support business-critical systems.

Technical summary

The public record identifies this issue as a privilege escalation vulnerability in Microsoft Active Directory Domain Services. CISA’s KEV entry marks it as actively exploited and notes known ransomware campaign use. The supplied sources do not provide additional technical mechanics, so operational focus should be on prompt vendor-guided remediation and exposure reduction.

Defensive priority

Critical. CISA designated the issue as known exploited and assigned a remediation due date of 2022-05-02 in the KEV catalog, which makes it a top-priority patching and validation item for Microsoft Active Directory environments.

Recommended defensive actions

  • Apply Microsoft updates per vendor instructions as soon as possible.
  • Prioritize patching domain controllers and other Active Directory Domain Services systems first.
  • Confirm the environment is covered by current vulnerability and patch management processes for KEV-listed issues.
  • Review identity and administrative access controls around Active Directory to reduce the impact of privilege escalation.
  • Validate remediation after patching and track any unpatched or exception-based systems until fully updated.

Evidence notes

This debrief is based only on the supplied source corpus and official links: the CISA KEV source item identifies Microsoft Active Directory Domain Services as the affected product, classifies the vulnerability as known exploited, notes known ransomware campaign use, and directs users to apply updates per vendor instructions. The provided CVE and timeline fields place public cataloging at 2022-04-11, with KEV due date 2022-05-02. No CVSS score was supplied in the corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2021-42278 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2021-42278

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2021-42278 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2021-42278

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.