EXPOSURES › CVE-2021-36948
CVE-2021-36948
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unpatched privilege escalation flaw in Windows Update Medic Service was actively exploited in the wild, allowing attackers to escalate privileges on Windows systems.
This unpatched vulnerability in the Windows Update Medic Service allows attackers to escalate privileges, potentially leading to full system compromise. DIB organizations must ensure timely patching of Windows systems, as this flaw was actively exploited in the wild and is now on CISA's KEV catalog. The failure highlights the critical importance of maintaining up-to-date systems to prevent privilege escalation attacks.
Shame score — The vulnerability was unpatched and actively exploited in the wild, demonstrating a failure to patch known flaws and leaving systems vulnerable to privilege escalation attacks.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation.
"Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation."
"CVE-2026-62870 Microsoft 5 365 Apps , Excel 2016 , Office 2019 and 2 more"
"CVE-2026-60586 1 Oracle 3 Mysql Connector/j , Mysql Connector/j , Mysql Connectors"
"7-Eleven (2026, 281.3K records)"
"Critical N-able N-central Vulnerability and Active Exploitation"
"Microsoft Security Blog"
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |