Patch Tuesday Archive
Patch Tuesday July 2021
Total CVEs
157
Critical
13
Important
109
Exploited
4
Publicly Disclosed
9
All CVEs this month 157
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| ADV210003 | Mitigating NTLM Relay Attacks on Active Directory Certificate Services (AD CS) | Moderate | - | Windows NTLM | - | Yes | - |
| CVE-2021-30541 | Chromium: CVE-2021-30541 Use after free in V8 | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30559 | Chromium: CVE-2021-30559 Out of bounds write in ANGLE | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30560 | Chromium: CVE-2021-30560 Use after free in Blink XSLT | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30561 | Chromium: CVE-2021-30561 Type Confusion in V8 | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30562 | Chromium: CVE-2021-30562 Use after free in WebSerial | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30563 | Chromium: CVE-2021-30563 Type Confusion in V8 | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30564 | Chromium: CVE-2021-30564 Heap buffer overflow in WebXR | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30565 | Chromium: CVE-2021-30565 Out of bounds write in Tab Groups | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30566 | Chromium: CVE-2021-30566 Stack buffer overflow in Printing | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30567 | Chromium: CVE-2021-30567 Use after free in DevTools | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30568 | Chromium: CVE-2021-30568 Heap buffer overflow in WebGL | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30569 | Chromium: CVE-2021-30569 Use after free in sqlite | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30571 | Chromium: CVE-2021-30571 Insufficient policy enforcement in DevTools | 9.6 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30572 | Chromium: CVE-2021-30572 Use after free in Autofill | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30573 | Chromium: CVE-2021-30573 Use after free in GPU | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30574 | Chromium: CVE-2021-30574 Use after free in protocol handling | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30575 | Chromium: CVE-2021-30575 Out of bounds read in Autofill | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30576 | Chromium: CVE-2021-30576 Use after free in DevTools | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30577 | Chromium: CVE-2021-30577 Insufficient policy enforcement in Installer | 7.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30578 | Chromium: CVE-2021-30578 Uninitialized Use in Media | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30579 | Chromium: CVE-2021-30579 Use after free in UI framework | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30580 | Chromium: CVE-2021-30580 Insufficient policy enforcement in Android intents | 6.5 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30581 | Chromium: CVE-2021-30581 Use after free in DevTools | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30582 | Chromium: CVE-2021-30582 Inappropriate implementation in Animation | 6.5 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30583 | Chromium: CVE-2021-30583 Insufficient policy enforcement in image handling on Windows | 6.5 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30584 | Chromium: CVE-2021-30584 Incorrect security UI in Downloads | 6.5 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30585 | Chromium: CVE-2021-30585 Use after free in sensor handling | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30586 | Chromium: CVE-2021-30586 Use after free in dialog box handling on Windows | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30587 | Chromium: CVE-2021-30587 Inappropriate implementation in Compositing on Windows | 4.3 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30588 | Chromium: CVE-2021-30588 Type Confusion in V8 | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-30589 | Chromium: CVE-2021-30589 Insufficient validation of untrusted input in Sharing | 4.3 |
Microsoft Edge (Chromium-based) | - | - | - | |
| CVE-2021-31183 | Windows TCP/IP Driver Denial of Service Vulnerability | Important | 7.5 |
Windows TCP/IP | - | - | - |
| CVE-2021-31196 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 7.2 |
Microsoft Exchange Server | - | - | - |
| CVE-2021-31206 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 7.6 |
Microsoft Exchange Server | - | - | - |
| CVE-2021-31947 | HEVC Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-31961 | Windows InstallService Elevation of Privilege Vulnerability | Important | 6.1 |
Windows Installer | - | - | - |
| CVE-2021-31979 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | Yes | - | - |
| CVE-2021-31984 | Power BI Remote Code Execution Vulnerability | Important | 7.6 |
Power BI | - | - | - |
| CVE-2021-32740 | Regular Expression Denial of Service in Addressable templates | Important | 7.5 |
Mariner | - | - | - |
| CVE-2021-33740 | Windows Media Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-33743 | Windows Projected File System Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Projected File System | - | - | - |
| CVE-2021-33744 | Windows Secure Kernel Mode Security Feature Bypass Vulnerability | Important | 5.3 |
Windows Secure Kernel Mode | - | - | - |
| CVE-2021-33745 | Windows DNS Server Denial of Service Vulnerability | Important | 6.5 |
Role: DNS Server | - | - | - |
| CVE-2021-33746 | Windows DNS Server Remote Code Execution Vulnerability | Important | 8 |
Windows DNS | - | - | - |
| CVE-2021-33749 | Windows DNS Snap-in Remote Code Execution Vulnerability | Important | 8.8 |
Role: DNS Server | - | - | - |
| CVE-2021-33750 | Windows DNS Snap-in Remote Code Execution Vulnerability | Important | 8.8 |
Role: DNS Server | - | - | - |
| CVE-2021-33751 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | Important | 7 |
Windows Storage Spaces Controller | - | - | - |
| CVE-2021-33752 | Windows DNS Snap-in Remote Code Execution Vulnerability | Important | 8.8 |
Role: DNS Server | - | - | - |
| CVE-2021-33753 | Microsoft Bing Search Spoofing Vulnerability | Important | 4.7 |
Microsoft Bing | - | - | - |
| CVE-2021-33754 | Windows DNS Server Remote Code Execution Vulnerability | Important | 8 |
Windows DNS | - | - | - |
| CVE-2021-33755 | Windows Hyper-V Denial of Service Vulnerability | Important | 6.3 |
Role: Windows Hyper-V | - | - | - |
| CVE-2021-33756 | Windows DNS Snap-in Remote Code Execution Vulnerability | Important | 8.8 |
Role: DNS Server | - | - | - |
| CVE-2021-33757 | Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability | Important | 5.3 |
Windows Security Account Manager | - | - | - |
| CVE-2021-33758 | Windows Hyper-V Denial of Service Vulnerability | Important | 7.7 |
Role: Windows Hyper-V | - | - | - |
| CVE-2021-33759 | Windows Desktop Bridge Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Desktop Bridge | - | - | - |
| CVE-2021-33760 | Media Foundation Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows Codecs Library | - | - | Yes |
| CVE-2021-33761 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Remote Access Connection Manager | - | - | - |
| CVE-2021-33763 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | Important | 5.5 |
Windows Remote Access Connection Manager | - | - | - |
| CVE-2021-33764 | Windows Key Distribution Center Information Disclosure Vulnerability | Important | 5.9 |
Windows Key Distribution Center | - | - | - |
| CVE-2021-33765 | Windows Installer Spoofing Vulnerability | Important | 6.2 |
Windows Installer | - | - | - |
| CVE-2021-33766 | Microsoft Exchange Server Information Disclosure Vulnerability | Important | 7.3 |
Microsoft Exchange Server | - | - | - |
| CVE-2021-33767 | Open Enclave SDK Elevation of Privilege Vulnerability | Important | 8.2 |
OpenEnclave | - | - | - |
| CVE-2021-33768 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Important | 8 |
Microsoft Exchange Server | - | - | - |
| CVE-2021-33771 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | Yes | - | - |
| CVE-2021-33772 | Windows TCP/IP Driver Denial of Service Vulnerability | Important | 7.5 |
Windows TCP/IP | - | - | - |
| CVE-2021-33773 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Remote Access Connection Manager | - | - | - |
| CVE-2021-33774 | Windows Event Tracing Elevation of Privilege Vulnerability | Important | 7 |
Windows Event Tracing | - | - | - |
| CVE-2021-33775 | HEVC Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-33776 | HEVC Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-33777 | HEVC Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-33778 | HEVC Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-33779 | Windows AD FS Security Feature Bypass Vulnerability | Important | 8.1 |
Active Directory Federation Services (AD FS) | - | Yes | - |
| CVE-2021-33780 | Windows DNS Server Remote Code Execution Vulnerability | Important | 8.8 |
Role: DNS Server | - | - | - |
| CVE-2021-33781 | Azure AD Security Feature Bypass Vulnerability | Important | 8.1 |
Windows Active Directory | - | Yes | - |
| CVE-2021-33782 | Windows Authenticode Spoofing Vulnerability | Important | 5.5 |
Windows Authenticode | - | - | - |
| CVE-2021-33783 | Windows SMB Information Disclosure Vulnerability | Important | 6.5 |
Windows SMB | - | - | - |
| CVE-2021-33784 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Cloud Files Mini Filter Driver | - | - | - |
| CVE-2021-33785 | Windows AF_UNIX Socket Provider Denial of Service Vulnerability | Important | 7.5 |
Windows AF_UNIX Socket Provider | - | - | - |
| CVE-2021-33786 | Windows LSA Security Feature Bypass Vulnerability | Important | 8.1 |
Windows Local Security Authority Subsystem Service (LSASS) | - | - | - |
| CVE-2021-33788 | Windows LSA Denial of Service Vulnerability | Important | 7.5 |
Windows Local Security Authority Subsystem Service (LSASS) | - | - | - |
| CVE-2021-33910 | basic/unit-name.c in systemd prior to 246.15 247.8 248.5 and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash. | Moderate | 5.5 |
Mariner | - | - | - |
| CVE-2021-34438 | Windows Font Driver Host Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2021-34439 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Windows Media Foundation | - | - | - |
| CVE-2021-34440 | GDI+ Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2021-34441 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Media Foundation | - | - | - |
| CVE-2021-34442 | Windows DNS Server Remote Code Execution Vulnerability | Important | 8.8 |
Role: DNS Server | - | - | - |
| CVE-2021-34444 | Windows DNS Server Denial of Service Vulnerability | Important | 6.5 |
Role: DNS Server | - | - | - |
| CVE-2021-34445 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Remote Access Connection Manager | - | - | - |
| CVE-2021-34446 | Windows HTML Platforms Security Feature Bypass Vulnerability | Important | 8 |
Windows HTML Platform | - | - | - |
| CVE-2021-34447 | Windows MSHTML Platform Remote Code Execution Vulnerability | Important | 6.8 |
Windows MSHTML Platform | - | - | - |
| CVE-2021-34448 | Scripting Engine Memory Corruption Vulnerability | Critical | 6.8 |
Microsoft Scripting Engine | Yes | - | - |
| CVE-2021-34449 | Win32k Elevation of Privilege Vulnerability | Important | 7 |
Windows Win32K | - | - | - |
| CVE-2021-34450 | Windows Hyper-V Remote Code Execution Vulnerability | Critical | 8.5 |
Role: Windows Hyper-V | - | - | - |
| CVE-2021-34451 | Microsoft Office Online Server Spoofing Vulnerability | Important | 5.3 |
Microsoft Office | - | - | - |
| CVE-2021-34452 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2021-34454 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | Important | 5.5 |
Windows Shell | - | - | - |
| CVE-2021-34455 | Windows File History Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows File History Service | - | - | - |
| CVE-2021-34456 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Remote Access Connection Manager | - | - | - |
| CVE-2021-34457 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | Important | 5.5 |
Windows Remote Access Connection Manager | - | - | - |
| CVE-2021-34458 | Windows Kernel Remote Code Execution Vulnerability | Critical | 9.9 |
Windows Kernel | - | - | - |
| CVE-2021-34459 | Windows AppContainer Elevation Of Privilege Vulnerability | Important | 7.8 |
Windows AppContainer | - | - | - |
| CVE-2021-34460 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Storage Spaces Controller | - | - | - |
| CVE-2021-34461 | Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2021-34462 | Windows AppX Deployment Extensions Elevation of Privilege Vulnerability | Important | 7 |
Windows AppX Deployment Extensions | - | - | - |
| CVE-2021-34464 | Microsoft Defender Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Defender | - | - | - |
| CVE-2021-34466 | Windows Hello Security Feature Bypass Vulnerability | Important | 5.7 |
Windows Hello | - | - | - |
| CVE-2021-34467 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 7.1 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-34468 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 7.1 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-34469 | Microsoft Office Security Feature Bypass Vulnerability | Important | 8.2 |
Microsoft Office | - | - | - |
| CVE-2021-34470 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Important | 8 |
Microsoft Exchange Server | - | - | - |
| CVE-2021-34473 | Microsoft Exchange Server Remote Code Execution Vulnerability | Critical | 9.1 |
Microsoft Exchange Server | - | Yes | - |
| CVE-2021-34474 | Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability | Critical | 8 |
Dynamics Business Central Control | - | - | - |
| CVE-2021-34476 | Bowser.sys Denial of Service Vulnerability | Important | 7.5 |
Common Internet File System | - | - | - |
| CVE-2021-34477 | Visual Studio Code .NET Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Visual Studio Code - .NET Runtime | - | - | - |
| CVE-2021-34479 | Microsoft Visual Studio Spoofing Vulnerability | Important | 7.8 |
Visual Studio Code | - | - | - |
| CVE-2021-34481 | Windows Print Spooler Remote Code Execution Vulnerability | Important | 8.8 |
Windows Print Spooler Components | - | Yes | - |
| CVE-2021-34488 | Windows Console Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Console Driver | - | - | - |
| CVE-2021-34489 | DirectWrite Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2021-34490 | Windows TCP/IP Driver Denial of Service Vulnerability | Important | 7.5 |
Windows TCP/IP | - | - | - |
| CVE-2021-34491 | Win32k Information Disclosure Vulnerability | Important | 5.5 |
Windows Win32K | - | - | - |
| CVE-2021-34492 | Windows Certificate Spoofing Vulnerability | Important | 8.1 |
Windows PFX Encryption | - | Yes | - |
| CVE-2021-34493 | Windows Partition Management Driver Elevation of Privilege Vulnerability | Important | 6.7 |
Windows Partition Management Driver | - | - | - |
| CVE-2021-34494 | Windows DNS Server Remote Code Execution Vulnerability | Critical | 8.8 |
Role: DNS Server | - | - | - |
| CVE-2021-34496 | Windows GDI Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2021-34497 | Windows MSHTML Platform Remote Code Execution Vulnerability | Critical | 6.8 |
Windows MSHTML Platform | - | - | - |
| CVE-2021-34498 | Windows GDI Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2021-34499 | Windows DNS Server Denial of Service Vulnerability | Important | 6.5 |
Windows DNS | - | - | - |
| CVE-2021-34500 | Windows Kernel Memory Information Disclosure Vulnerability | Important | 6.3 |
Windows Kernel | - | - | - |
| CVE-2021-34501 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2021-34503 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Windows Media Foundation | - | - | Yes |
| CVE-2021-34504 | Windows Address Book Remote Code Execution Vulnerability | Important | 7.8 |
Windows Address Book | - | - | - |
| CVE-2021-34507 | Windows Remote Assistance Information Disclosure Vulnerability | Important | 6.5 |
Windows Remote Assistance | - | - | - |
| CVE-2021-34508 | Windows Kernel Remote Code Execution Vulnerability | Important | 8.8 |
Windows Kernel | - | - | - |
| CVE-2021-34509 | Storage Spaces Controller Information Disclosure Vulnerability | Important | 5.5 |
Windows Storage Spaces Controller | - | - | - |
| CVE-2021-34510 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Storage Spaces Controller | - | - | - |
| CVE-2021-34511 | Windows Installer Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Installer | - | - | - |
| CVE-2021-34512 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Storage Spaces Controller | - | - | - |
| CVE-2021-34513 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Storage Spaces Controller | - | - | - |
| CVE-2021-34514 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2021-34516 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K | - | - | - |
| CVE-2021-34517 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.3 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-34518 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2021-34519 | Microsoft SharePoint Server Information Disclosure Vulnerability | Moderate | 5.3 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-34520 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 8.1 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-34521 | Raw Image Extension Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-34522 | Microsoft Defender Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Defender | - | - | - |
| CVE-2021-34523 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Important | 9 |
Microsoft Exchange Server | - | Yes | - |
| CVE-2021-34525 | Windows DNS Server Remote Code Execution Vulnerability | Important | 8.8 |
Role: DNS Server | - | - | - |
| CVE-2021-34527 | Windows Print Spooler Remote Code Execution Vulnerability | Critical | 8.8 |
Windows Print Spooler Components | Yes | Yes | - |
| CVE-2021-34528 | Visual Studio Code Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio Code | - | - | - |
| CVE-2021-34529 | Visual Studio Code Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio Code | - | - | - |
| CVE-2021-34558 | The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange allowing a malicious TLS server to cause a TLS client to panic. | Moderate | 6.5 |
Mariner | - | - | - |
| CVE-2021-36928 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 6 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2021-36929 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Important | 6.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2021-36931 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 4.4 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2021-36934 | Windows Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows | - | Yes | - |
Threat Categories 7
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 46 | 13 |
| Elevation of Privilege | 35 | - |
| Unknown | 34 | - |
| Information Disclosure | 15 | - |
| Denial of Service | 11 | - |
| Security Feature Bypass | 8 | - |
| Spoofing | 8 | - |
Affected Products 55
| Product | CVEs | Exploited |
|---|---|---|
| Microsoft Edge (Chromium-based) | 34 | - |
| Role: DNS Server | 10 | - |
| Microsoft Windows Codecs Library | 8 | - |
| Microsoft Exchange Server | 7 | - |
| Windows Kernel | 7 | 2 |
| Windows Remote Access Connection Manager | 6 | - |
| Windows Storage Spaces Controller | 6 | - |
| Microsoft Graphics Component | 5 | - |
| Microsoft Office SharePoint | 5 | - |
| Mariner | 3 | - |
| Microsoft Office | 3 | - |
| Microsoft Windows Media Foundation | 3 | - |
| Role: Windows Hyper-V | 3 | - |
| Visual Studio Code | 3 | - |
| Windows DNS | 3 | - |
| Windows Installer | 3 | - |
| Windows TCP/IP | 3 | - |
| Windows Win32K | 3 | - |
| Microsoft Defender | 2 | - |
| Microsoft Office Excel | 2 | - |
| Windows Local Security Authority Subsystem Service (LSASS) | 2 | - |
| Windows MSHTML Platform | 2 | - |
| Windows Print Spooler Components | 2 | 1 |
| Active Directory Federation Services (AD FS) | 1 | - |
| Common Internet File System | 1 | - |
| Dynamics Business Central Control | 1 | - |
| Microsoft Bing | 1 | - |
| Microsoft Scripting Engine | 1 | 1 |
| Microsoft Windows | 1 | - |
| OpenEnclave | 1 | - |
| Power BI | 1 | - |
| Visual Studio Code - .NET Runtime | 1 | - |
| Windows AF_UNIX Socket Provider | 1 | - |
| Windows Active Directory | 1 | - |
| Windows Address Book | 1 | - |
| Windows AppContainer | 1 | - |
| Windows AppX Deployment Extensions | 1 | - |
| Windows Authenticode | 1 | - |
| Windows Cloud Files Mini Filter Driver | 1 | - |
| Windows Console Driver | 1 | - |
| Windows Desktop Bridge | 1 | - |
| Windows Event Tracing | 1 | - |
| Windows File History Service | 1 | - |
| Windows HTML Platform | 1 | - |
| Windows Hello | 1 | - |
| Windows Key Distribution Center | 1 | - |
| Windows NTLM | 1 | - |
| Windows PFX Encryption | 1 | - |
| Windows Partition Management Driver | 1 | - |
| Windows Projected File System | 1 | - |
| Windows Remote Assistance | 1 | - |
| Windows SMB | 1 | - |
| Windows Secure Kernel Mode | 1 | - |
| Windows Security Account Manager | 1 | - |
| Windows Shell | 1 | - |