CVE-2021-2707011.03.2021, 16:15Windows 10 Update Assistant Elevation of Privilege VulnerabilityEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST7.3 HIGHLOCALLOWLOWCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HmicrosoftCNA7.3 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:CCVEADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 87%Common Weakness EnumerationCWE-732 - Incorrect Permission Assignment for Critical ResourceThe product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.Referenceshttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-27070https://www.zerodayinitiative.com/advisories/ZDI-21-329/https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-27070https://www.zerodayinitiative.com/advisories/ZDI-21-329/