Security readout for executives and security teams
Plain-English summary
CVE-2021-1702 is a Windows privilege escalation flaw in the Remote Procedure Call runtime. It does not describe remote initial access; the attacker needs local low-privileged access. If exploited, it could let them gain broad control of confidentiality, integrity, and availability on the affected Windows host.
Executive priority
Treat as high priority for Windows patch management, especially on shared or exposed operational hosts. It is not evidenced as actively exploited in the provided sources, but successful exploitation could materially increase attacker control after initial access.
Technical view
Microsoft rates this RPC Runtime elevation-of-privilege issue CVSS 7.8: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The source bundle lists many Windows client and server releases from Windows 7/Server 2008 through Windows 10/Server 20H2. Official Microsoft remediation is indicated, but no technical root cause is included.
Likely exposure
Exposure is likely on unpatched affected Windows desktops, servers, Server Core installations, VDI, jump hosts, and multi-user systems where low-privileged users or attackers can run code locally.
Exploitation context
The bundle does not show CISA KEV status or cited active exploitation. Exploitability is local, low complexity, and requires low privileges but no user interaction, making it most relevant after phishing, credential theft, or insider access.
Researcher notes
Public details in the bundle are sparse. Use MSRC as authoritative for product applicability and remediation. The bundled affected CPE data contains repeated or inconsistent Windows 10 entries, so validate against Microsoft’s update guide before scoping.
Mitigation direction
- Apply the applicable Microsoft security update for CVE-2021-1702.
- Prioritize shared servers, VDI, jump hosts, and systems with local user access.
- Check Microsoft guidance for affected builds, KBs, and supersedence details.
- Restrict local logon and code execution paths where patching is delayed.
Validation and detection
- Inventory Windows versions against the Microsoft affected product list.
- Confirm the CVE-2021-1702 security update is installed or superseded.
- Review vulnerability scanner results for stale Windows build detection.
- Verify higher-risk multi-user hosts are patched first.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Privilege behavior lookup
The CVE wording references privilege impact, so privilege escalation and authorization behavior review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2021-1702 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.8 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C1.85.9Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7.8HighVector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Source materials
- CVE List V5 sourceCVE List V5
- Windows Remote Procedure Call Runtime Elevation of Privilege VulnerabilityCVE reference · vendor-advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1702CVE reference · x_refsource_MISC, x_transferred
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
