Описание
Multiple vulnerabilities were found in Microsoft Products (ESU). Malicious users can exploit these vulnerabilities to cause denial of service, execute arbitrary code, gain privileges, obtain sensitive information, spoof user interface.
Below is a complete list of vulnerabilities:
- A memory corruption vulnerability in Windows Scripting Engine can be exploited remotely to execute arbitrary code.
- An elevation of privilege vulnerability in Windows Common Log File System Driver can be exploited remotely to gain privileges.
- A spoofing vulnerability in Windows Authenticode can be exploited remotely to spoof user interface.
- An information disclosure vulnerability in Windows SMB can be exploited remotely to obtain sensitive information.
- A denial of service vulnerability in Windows Installer can be exploited remotely to cause denial of service.
- An information disclosure vulnerability in Windows Installer can be exploited remotely to obtain sensitive information.
- An elevation of privilege vulnerability in Windows Event Tracing can be exploited remotely to gain privileges.
- A remote code execution vulnerability in Windows WLAN AutoConfig Service can be exploited remotely to execute arbitrary code.
- An elevation of privilege vulnerability in Windows DNS can be exploited remotely to gain privileges.
- An information disclosure vulnerability in Windows Redirected Drive Buffering SubSystem Driver can be exploited remotely to obtain sensitive information.
- An elevation of privilege vulnerability in Windows SMB can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Kernel can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Ancillary Function Driver for WinSock can be exploited remotely to gain privileges.
- An information disclosure vulnerability in Windows Ancillary Function Driver for WinSock can be exploited remotely to obtain sensitive information.
- An elevation of privilege vulnerability in Win32k can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Print Spooler can be exploited remotely to gain privileges.
Первичный источник обнаружения
- CVE-2021-38635
CVE-2021-36962
CVE-2021-38628
CVE-2021-36961
CVE-2021-38671
CVE-2021-26435
CVE-2021-38630
CVE-2021-36969
CVE-2021-36955
CVE-2021-38638
CVE-2021-36964
CVE-2021-38629
CVE-2021-40447
CVE-2021-38639
CVE-2021-36959
CVE-2021-38667
CVE-2021-38626
CVE-2021-38636
CVE-2021-36960
CVE-2021-36965
CVE-2021-36968
CVE-2021-36963
CVE-2021-38625
CVE-2021-38633
CVE-2021-36972
CVE-2021-36974
Эксплуатация
Public exploits exist for this vulnerability.
Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.
Связанные продукты
- Microsoft-Windows
- Microsoft-Windows-Server
- Microsoft-Windows-Server-2012
- Microsoft-Windows-8
- Microsoft-Windows-7
- Microsoft-Windows-Server-2008
- Windows-RT
- Microsoft-Windows-10
- Microsoft-Windows-Server-2016
- Microsoft-Windows-Server-2019
Список CVE
- CVE-2021-38635 high
- CVE-2021-36962 high
- CVE-2021-38628 critical
- CVE-2021-36961 high
- CVE-2021-38671 critical
- CVE-2021-26435 critical
- CVE-2021-38630 critical
- CVE-2021-36969 high
- CVE-2021-36955 critical
- CVE-2021-38638 critical
- CVE-2021-36964 critical
- CVE-2021-38629 high
- CVE-2021-40447 critical
- CVE-2021-38639 critical
- CVE-2021-36959 high
- CVE-2021-38667 critical
- CVE-2021-38626 critical
- CVE-2021-38636 high
- CVE-2021-36960 critical
- CVE-2021-36965 critical
- CVE-2021-36968 critical
- CVE-2021-36963 critical
- CVE-2021-38625 critical
- CVE-2021-38633 critical
- CVE-2021-36972 unknown
- CVE-2021-36974 unknown
Список KB
Смотрите также
Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com
Нашли неточность в описании этой уязвимости? Дайте нам знать!