Security
Headlines
HeadlinesLatestCVEs

Tag

#Security Vulnerability

CVE-2021-36960: Windows SMB Information Disclosure Vulnerability

*What type of information could be disclosed by this vulnerability?* The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory and kernel memory - unintentional read access to memory contents in kernel space from a user mode process.

Microsoft Security Response Center
#Windows SMB#Security Vulnerability#vulnerability#windows
CVE-2021-38669: Microsoft Edge (Chromium-based) Tampering Vulnerability

*What is the version information for this release?* Microsoft Edge Version Date Released Based on Chromium Version 93.0.961.44 9/9/2021 93.04577.63

CVE-2021-40444: Microsoft MSHTML Remote Code Execution Vulnerability

By default, Microsoft Office opens documents from the internet in Protected View or Application Guard for Office both of which prevent the current attack. * For information about Protected View, see What is Protected View?. * For information about Application Guard for Office, see Application Guard for Office. Customers of Microsoft Defender for Endpoint can enable attack surface reduction rule "BlockOfficeCreateProcessRule" that blocks Office apps from creating child processes. Creating malicious child processes is a common malware strategy. For more information see Use attack surface reduction rules to prevent malware infection.

CVE-2021-30618: Chromium: CVE-2021-30618 Inappropriate implementation in DevTools

*What is the version information for this release?* | Microsoft Edge Version | Date Released | Based on Chromium Version | | ----- | ----- | ----- | | 93.0.961.38 | 9/2/2021 | 93.0.4577.63 |

CVE-2021-30617: Chromium: CVE-2021-30617 Policy bypass in Blink

*What is the version information for this release?* | Microsoft Edge Version | Date Released | Based on Chromium Version | | ----- | ----- | ----- | | 93.0.961.38 | 9/2/2021 | 93.0.4577.63 |

CVE-2021-30616: Chromium: CVE-2021-30616 Use after free in Media

*What is the version information for this release?* | Microsoft Edge Version | Date Released | Based on Chromium Version | | ----- | ----- | ----- | | 93.0.961.38 | 9/2/2021 | 93.0.4577.63 |

CVE-2021-30615: Chromium: CVE-2021-30615 Cross-origin data leak in Navigation

*What is the version information for this release?* | Microsoft Edge Version | Date Released | Based on Chromium Version | | ----- | ----- | ----- | | 93.0.961.38 | 9/2/2021 | 93.0.4577.63 |

CVE-2021-30614: Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip

*What is the version information for this release?* | Microsoft Edge Version | Date Released | Based on Chromium Version | | ----- | ----- | ----- | | 93.0.961.38 | 9/2/2021 | 93.0.4577.63 |

CVE-2021-30613: Chromium: CVE-2021-30613 Use after free in Base internals

*What is the version information for this release?* | Microsoft Edge Version | Date Released | Based on Chromium Version | | ----- | ----- | ----- | | 93.0.961.38 | 9/2/2021 | 93.0.4577.63 |

CVE-2021-30612: Chromium: CVE-2021-30612 Use after free in WebRTC

*What is the version information for this release?* | Microsoft Edge Version | Date Released | Based on Chromium Version | | ----- | ----- | ----- | | 93.0.961.38 | 9/2/2021 | 93.0.4577.63 |