Security readout for executives and security teams
Plain-English summary
CVE-2021-28328 is a Microsoft Windows DNS information disclosure issue. The public bundle indicates an attacker with low privileges and network access could expose sensitive information, but it does not describe data types or business impact specifics.
Executive priority
Handle through normal-to-elevated patch governance, with priority for exposed servers and legacy Windows estates. The risk is confidentiality-focused and moderate, but broad Windows coverage makes asset inventory important.
Technical view
The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, score 6.5. Impact is confidentiality only, with no stated integrity or availability effect. The bundle does not include root-cause details, exploit mechanics, or a named workaround.
Likely exposure
Exposure is most relevant to organizations still running affected Windows client or server versions listed by Microsoft, including Windows 7/8.1/10 and Windows Server 2008, 2016, 2019, and related Server Core releases.
Exploitation context
The provided bundle does not support active exploitation. KEV is false, and the CVSS exploit maturity is unproven. Treat exploitability as plausible from the network with low privileges, but not confirmed as exploited in the wild here.
Researcher notes
Evidence is thin beyond Microsoft/NVD-style metadata. Avoid assuming DNS server-only exposure or public exploit availability. Useful follow-up is validating Microsoft’s advisory details and mapping installed KB levels to affected operating systems.
Mitigation direction
- Review Microsoft MSRC guidance for CVE-2021-28328.
- Apply applicable Microsoft security updates through approved patch management.
- Prioritize internet-facing or sensitive Windows DNS-related assets.
- Retire or isolate unsupported Windows versions where updates are unavailable.
Validation and detection
- Inventory Windows versions against the affected product list.
- Confirm April 2021 or later relevant Microsoft updates are installed.
- Check vulnerability scanner findings for CVE-2021-28328.
- Verify unsupported systems have compensating controls or migration plans.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-28328 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 6.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C2.83.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
6.5MediumVector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Source materials
- CVE List V5 sourceCVE List V5
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-28328CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
