Kaspersky ID:
KLA12112
Detect Date:
03/09/2021
Updated:
01/25/2024

Description

Multiple vulnerabilities were found in Microsoft Products (Extended Security Update). Malicious users can exploit these vulnerabilities to execute arbitrary code, gain privileges, cause denial of service, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A memory corruption vulnerability in Internet Explorer can be exploited remotely to execute arbitrary code.
  2. An elevation of privilege vulnerability in Windows UPnP Device Host can be exploited remotely to gain privileges.
  3. An elevation of privilege vulnerability in Windows Win32k can be exploited remotely to gain privileges.
  4. A denial of service vulnerability in Windows DNS Server can be exploited remotely to cause denial of service.
  5. A remote code execution vulnerability in Windows DNS Server can be exploited remotely to execute arbitrary code.
  6. An information disclosure vulnerability in Windows Event Tracing can be exploited remotely to obtain sensitive information.
  7. An elevation of privilege vulnerability in Windows Print Spooler can be exploited remotely to gain privileges.
  8. An elevation of privilege vulnerability in Windows Event Tracing can be exploited remotely to gain privileges.
  9. An information disclosure vulnerability in Windows ActiveX Installer Service can be exploited remotely to obtain sensitive information.
  10. A remote code execution vulnerability in Windows Graphics Component can be exploited remotely to execute arbitrary code.
  11. A remote code execution vulnerability in Microsoft Windows Media Foundation can be exploited remotely to execute arbitrary code.
  12. An elevation of privilege vulnerability in Remote Access API can be exploited remotely to gain privileges.
  13. An elevation of privilege vulnerability in Windows Installer can be exploited remotely to gain privileges.
  14. An elevation of privilege vulnerability in Windows User Profile Service can be exploited remotely to gain privileges.
  15. An elevation of privilege vulnerability in Microsoft Windows Folder Redirection can be exploited remotely to gain privileges.

Original advisories

Exploitation

Public exploits exist for this vulnerability.

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Related products

CVE list

  • CVE-2021-26411
    critical
  • CVE-2021-26899
    critical
  • CVE-2021-26875
    critical
  • CVE-2021-27063
    critical
  • CVE-2021-26895
    critical
  • CVE-2021-24107
    high
  • CVE-2021-26887
    critical
  • CVE-2021-26878
    critical
  • CVE-2021-27077
    critical
  • CVE-2021-26894
    critical
  • CVE-2021-26898
    critical
  • CVE-2021-26893
    critical
  • CVE-2021-26896
    critical
  • CVE-2021-26869
    high
  • CVE-2021-26877
    critical
  • CVE-2021-1640
    critical
  • CVE-2021-26897
    critical
  • CVE-2021-26872
    critical
  • CVE-2021-26861
    critical
  • CVE-2021-26901
    critical
  • CVE-2021-26881
    critical
  • CVE-2021-26882
    critical
  • CVE-2021-26862
    high
  • CVE-2021-26873
    high

KB list

Read more

Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com

Found an inaccuracy in the description of this vulnerability? Let us know!
Kaspersky Next
Let’s go Next: redefine your business’s cybersecurity
Learn more
New Kaspersky!
Your digital life deserves complete protection!
Learn more
Confirm changes?
Your message has been sent successfully.