Microsoft Monthly Security Update (December 2021)
RISK: Extremely High Risk
TYPE: Operating Systems - Windows OS

[Updated on 2025-10-08]
Updated Description, Source and Related Links.
CVE-2021-43226 is being exploited in the wild. Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.
Microsoft has released monthly security update for their products:
| Vulnerable Product | Risk Level | Impacts | Notes |
| Extended Security Updates (ESU) | Medium Risk | Elevation of Privilege Remote Code Execution Information Disclosure | CVE-2021-43226 is being exploited in the wild. Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms. |
| Windows | Medium Risk | Elevation of Privilege Remote Code Execution Information Disclosure Denial of Service | CVE-2021-43226 is being exploited in the wild. Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms. |
| System Center | Medium Risk | Remote Code Execution Elevation of Privilege Information Disclosure | |
| Developer Tools | Medium Risk | Remote Code Execution Elevation of Privilege Spoofing | |
| Microsoft Office | Medium Risk | Spoofing Remote Code Execution Elevation of Privilege Information Disclosure | |
| Device | Medium Risk | Remote Code Execution | |
| Apps | High Risk | Spoofing Remote Code Execution |
|
| Browser | Extremely High Risk | Remote Code Execution Security Restriction Bypass |
|
Number of 'Extremely High Risk' product(s): 1
Number of 'High Risk' product(s): 1
Number of 'Medium Risk' product(s): 6
Number of 'Low Risk' product(s): 0
Evaluation of overall 'Risk Level': Extremely High Risk
Impact
- Denial of Service
- Elevation of Privilege
- Remote Code Execution
- Security Restriction Bypass
- Information Disclosure
- Spoofing
System / Technologies affected
- Extended Security Updates (ESU)
- Windows
- System Center
- Developer Tools
- Microsoft Office
- Device
- Apps
- Browser
Solutions
Before installation of the software, please visit the vendor web-site for more details.
- Apply fixes issued by the vendor.
Vulnerability Identifier
Source
Related Link
Related Tags
Share with




