CVE-2021-36942
is CVE-2021-36942real, exploitable, or a false positive? Here's the community ground truth.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Windows LSA Spoofing Vulnerability
NVD only has a brief summary for this one — the community fills in the real-world detail below.
References
Published
Embed this verdict
[](https://www.truepositive.app/cve/CVE-2021-36942)<a href="https://www.truepositive.app/cve/CVE-2021-36942"><img src="https://www.truepositive.app/cve/CVE-2021-36942/badge.svg" alt="TruePositive verdict for CVE-2021-36942"></a>Live badge — updates automatically as the community verdict changes.
Community ground truth
Community verdict
2 verdictsIncludes TruePositive's curated baseline from public sources — community verdicts accrue on top.
to add your verdict.
Practitioners rate this higher than its CVSS — treat with extra caution.
Field notes & remediation
Verdicts are the quick signal — notes are the evidence and fixes behind them.
- 0
Confirmed exploited in the wild — listed in the CISA KEV catalog (added 2021-11-03). Linked to known ransomware campaigns. Treat as real and prioritize patching over triage.
Related CVEs
Same weakness — CWE-749.
- CVE-2010-0738CVSS 5.3KEVEPSS 79%
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
- CVE-2010-1428CVSS 7.5KEVEPSS 62%
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.