Windows Recovery Environment
by Microsoft
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-26431 | Hig | 0.51 | 7.8 | 0.01 | Aug 12, 2021 | Windows Recovery Environment Agent Elevation of Privilege Vulnerability | ||
| CVE-2024-38202 | Hig | 0.48 | 7.3 | 0.02 | Aug 8, 2024 | Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization Based Security… | ||
| CVE-2021-43239 | Hig | 0.46 | 7.1 | 0.01 | Dec 15, 2021 | Windows Recovery Environment Agent Elevation of Privilege Vulnerability | ||
| CVE-2025-21202 | Med | 0.40 | 6.1 | 0.01 | Jan 14, 2025 | Windows Recovery Environment Agent Elevation of Privilege Vulnerability | ||
| CVE-2026-20928 | Med | 0.30 | 4.6 | 0.00 | Apr 14, 2026 | Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack. |
- risk 0.51cvss 7.8epss 0.01
Windows Recovery Environment Agent Elevation of Privilege Vulnerability
- risk 0.48cvss 7.3epss 0.02
Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization Based Security…
- risk 0.46cvss 7.1epss 0.01
Windows Recovery Environment Agent Elevation of Privilege Vulnerability
- risk 0.40cvss 6.1epss 0.01
Windows Recovery Environment Agent Elevation of Privilege Vulnerability
- risk 0.30cvss 4.6epss 0.00
Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.