Security
Headlines
HeadlinesLatestCVEs

Source

Microsoft Security Response Center

CVE-2021-38631: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

*What type of information could be disclosed by this vulnerability?* The type of information that could be disclosed if an attacker successfully exploited this vulnerability is read access to Windows RDP client passwords by RDP server administrators.

Microsoft Security Response Center
#Windows RDP#Security Vulnerability#vulnerability#windows
CVE-2021-41371: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

*What type of information could be disclosed by this vulnerability?* The type of information that could be disclosed if an attacker successfully exploited this vulnerability is read access to Windows RDP client passwords by RDP server administrators.

CVE-2021-42275: Microsoft COM for Windows Remote Code Execution Vulnerability

*How could an attacker exploit this vulnerability?* An authorized attacker could exploit this Windows COM vulnerability by sending from a user mode application specially crafted malicious COM traffic directed at the COM Server, which might lead to remote code execution.

CVE-2021-42277: Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability

*What privileges does the attacker gain?* An attacker would only be able to delete targeted files on a system. They would not gain privileges to view or modify file contents.

CVE-2021-41379: Windows Installer Elevation of Privilege Vulnerability

*What privileges does the attacker gain?* An attacker would only be able to delete targeted files on a system. They would not gain privileges to view or modify file contents.

CVE-2021-42280: Windows Feedback Hub Elevation of Privilege Vulnerability

*What privileges does the attacker gain?* An attacker would only be able to delete targeted files on a system. They would not gain privileges to view or modify file contents.

CVE-2021-42287: Active Directory Domain Services Elevation of Privilege Vulnerability

*Where can I find more information about the improved authentication process added by the update for CVE-2021-42287?* See Authentication updates.

CVE-2021-42291: Active Directory Domain Services Elevation of Privilege Vulnerability

*Where can I find more information about Active Directory permissions updates?* See Active Directory permissions updates.

CVE-2021-42278: Active Directory Domain Services Elevation of Privilege Vulnerability

*Where can I find more information about Active Directory SAM Account hardening changes?* See Active Directory SAM Account hardening changes.

CVE-2021-38665: Remote Desktop Protocol Client Information Disclosure Vulnerability

*What type of information could be disclosed by this vulnerability?* Exploiting this vulnerability could allow the disclosure of initialized and/or uninitialized memory in the process heap.