CVE-2026-21513

HIGH(8.8)KEVErhöhtes Risiko

Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability

Beschreibung

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

KEV-Informationen

Hersteller
Microsoft
Produkt
Windows
Hinzugefügt am
10. Februar 2026
Fälligkeitsdatum
3. März 2026
Erforderliche Maßnahme
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS-Score

Vektorstring
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HIm Rechner öffnen
Angriffsvektor
NETWORK
Angriffskomplexität
LOW
Erforderliche Privilegien
NONE
Benutzerinteraktion
REQUIRED
Scope
UNCHANGED
Vertraulichkeitsauswirkung
HIGH
Integritätsauswirkung
HIGH
Verfügbarkeitsauswirkung
HIGH
Ausnutzbarkeitsscore
2.8
Auswirkungsscore
5.9

CWEs

Betroffene Produkte

HerstellerProduktVersion
microsoftwindows 10 1607< 10.0.14393.8868
microsoftwindows 10 1809< 10.0.17763.8389
microsoftwindows 10 21h2< 10.0.19044.6937
microsoftwindows 10 22h2< 10.0.19045.6937
microsoftwindows 11 23h2< 10.0.22631.6649
microsoftwindows 11 24h2< 10.0.26100.7781
microsoftwindows 11 25h2< 10.0.26200.7781
microsoftwindows server 2012-; r2
microsoftwindows server 2016< 10.0.14393.8868
microsoftwindows server 2019< 10.0.17763.8389
microsoftwindows server 2022< 10.0.20348.4711
microsoftwindows server 2022 23h2< 10.0.25398.2149
microsoftwindows server 2025< 10.0.26100.32313

Referenzen

CVSS-Score

8.8
HIGH(8.8)

EPSS-Score

EPSS-Score15.38%
EPSS-Perzentil96.4%

Daten

Veröffentlicht10. Februar 2026
Zuletzt geändert17. Juni 2026
StatusAnalyzed
CVSS-Versionv3.1

Hilfe beim Schwachstellenmanagement?

Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.