Security
Headlines
HeadlinesLatestCVEs

Tag

#microsoft

CVE-2021-40448: Microsoft Accessibility Insights for Android Information Disclosure Vulnerability

*What type of information could be disclosed by this vulnerability?* The type of information that could be disclosed if an attacker successfully exploited this vulnerability is sensitive information.

Microsoft Security Response Center
#Microsoft Accessibility Insights for Android#Security Vulnerability#vulnerability#android#microsoft
CVE-2021-38661: HEVC Video Extensions Remote Code Execution Vulnerability

*How do I get the updated app?* The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details. It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers. *My system is in a disconnected environment; is it vulnerable?* Customers using the Microsoft Store for Business and Microsoft Store for Education can get this update through their organizations. *How can I check if the update is installed?* If your device manufacturer preinstalled this app, package versions *1.0.42091.0* and later contain this update. If you purchased this app from the Microsoft Store, package versions *1.0.42094.0* and later contain this update. You can check the package version in PowerShell: Get-AppxPackage -Name Microsoft.HEVCVideoExtension*

CVE-2021-38657: Microsoft Office Graphics Component Information Disclosure Vulnerability

*What type of information could be disclosed by this vulnerability?* The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory.