CVE Notify
19.7K subscribers
4 photos
301K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2021-34456
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-34457
Windows Remote Access Connection Manager Information Disclosure Vulnerability

🎖@cveNotify
🚨 CVE-2021-34458
Windows Kernel Remote Code Execution Vulnerability

🎖@cveNotify
🚨 CVE-2021-34459
Windows AppContainer Elevation Of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-34460
Windows Storage Spaces Controller Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-34461
Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-34462
Windows AppX Deployment Extensions Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-34464
Microsoft Defender Remote Code Execution Vulnerability

🎖@cveNotify
🚨 CVE-2021-34466
Windows Hello Security Feature Bypass Vulnerability

🎖@cveNotify
🚨 CVE-2021-34467
Microsoft SharePoint Server Remote Code Execution Vulnerability

🎖@cveNotify
🚨 CVE-2021-34481
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
UPDATE August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see KB5005652.

🎖@cveNotify
🚨 CVE-2021-36934
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
An attacker must have the ability to execute code on a victim system to exploit this vulnerability.
After installing this security update, you must manually delete all shadow copies of system files, including the SAM database, to fully mitigate this vulnerabilty. Simply installing this security update will not fully mitigate this vulnerability. See KB5005357- Delete Volume Shadow Copies.

🎖@cveNotify
🚨 CVE-2021-26423
.NET Core and Visual Studio Denial of Service Vulnerability

🎖@cveNotify
🚨 CVE-2021-26424
Windows TCP/IP Remote Code Execution Vulnerability

🎖@cveNotify
🚨 CVE-2021-26425
Windows Event Tracing Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-26426
Windows User Account Profile Picture Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-26428
Azure Sphere Information Disclosure Vulnerability

🎖@cveNotify
🚨 CVE-2021-26429
Azure Sphere Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-26431
Windows Recovery Environment Agent Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-26432
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability

🎖@cveNotify
🚨 CVE-2021-26433
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability

🎖@cveNotify