CVE Notify
19.7K subscribers
4 photos
301K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2021-34462
Windows AppX Deployment Extensions Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-34464
Microsoft Defender Remote Code Execution Vulnerability

🎖@cveNotify
🚨 CVE-2021-34466
Windows Hello Security Feature Bypass Vulnerability

🎖@cveNotify
🚨 CVE-2021-34467
Microsoft SharePoint Server Remote Code Execution Vulnerability

🎖@cveNotify
🚨 CVE-2021-34481
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
UPDATE August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see KB5005652.

🎖@cveNotify
🚨 CVE-2021-36934
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
An attacker must have the ability to execute code on a victim system to exploit this vulnerability.
After installing this security update, you must manually delete all shadow copies of system files, including the SAM database, to fully mitigate this vulnerabilty. Simply installing this security update will not fully mitigate this vulnerability. See KB5005357- Delete Volume Shadow Copies.

🎖@cveNotify
🚨 CVE-2021-26423
.NET Core and Visual Studio Denial of Service Vulnerability

🎖@cveNotify
🚨 CVE-2021-26424
Windows TCP/IP Remote Code Execution Vulnerability

🎖@cveNotify
🚨 CVE-2021-26425
Windows Event Tracing Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-26426
Windows User Account Profile Picture Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-26428
Azure Sphere Information Disclosure Vulnerability

🎖@cveNotify
🚨 CVE-2021-26429
Azure Sphere Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-26431
Windows Recovery Environment Agent Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-26432
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability

🎖@cveNotify
🚨 CVE-2021-26433
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability

🎖@cveNotify
🚨 CVE-2021-33762
Azure CycleCloud Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-34471
Microsoft Defender Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-34478
Microsoft Office Remote Code Execution Vulnerability

🎖@cveNotify
🚨 CVE-2021-34480
Scripting Engine Memory Corruption Vulnerability

🎖@cveNotify
🚨 CVE-2021-34483
Windows Print Spooler Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-34484
Windows User Profile Service Elevation of Privilege Vulnerability

🎖@cveNotify