Security
Headlines
HeadlinesLatestCVEs

Source

Microsoft Security Response Center

CVE-2021-41332: Windows Print Spooler Information Disclosure Vulnerability

*What type of information could be disclosed by this vulnerability?* The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory.

Microsoft Security Response Center
#Windows Print Spooler Components#Security Vulnerability#vulnerability#windows
CVE-2021-26441: Storage Spaces Controller Elevation of Privilege Vulnerability

*How could an attacker exploit this vulnerability?* An authorized (medium integrity level) attacker could exploit this Windows Storport driver elevation of privilege vulnerability by locally sending through a user mode application a specially crafted request to the driver specifying an IOCTL parameter, which could lead to an out-of-bounds buffer write.

CVE-2021-40489: Storage Spaces Controller Elevation of Privilege Vulnerability

*How could an attacker exploit this vulnerability?* An authorized (medium integrity level) attacker could exploit this Windows Storport driver elevation of privilege vulnerability by locally sending through a user mode application a specially crafted request to the driver specifying an IOCTL parameter, which could lead to an out-of-bounds buffer write.

CVE-2021-37980: Chromium: CVE-2021-37980 Inappropriate implementation in Sandbox

*What is the version information for this release?* Microsoft Edge Version Date Released Based on Chromium Version 94.0.992.47 10/11/2021 94.0.4606.71

CVE-2021-37979: Chromium: CVE-2021-37979 Heap buffer overflow in WebRTC

*What is the version information for this release?* Microsoft Edge Version Date Released Based on Chromium Version 94.0.992.47 10/11/2021 94.0.4606.71

CVE-2021-37978: Chromium: CVE-2021-37978 Heap buffer overflow in Blink

*What is the version information for this release?* Microsoft Edge Version Date Released Based on Chromium Version 94.0.992.47 10/11/2021 94.0.4606.71

CVE-2021-37977: Chromium: CVE-2021-37977 Use after free in Garbage Collection

*What is the version information for this release?* Microsoft Edge Version Date Released Based on Chromium Version 94.0.992.47 10/11/2021 94.0.4606.71

CVE-2021-37976: Chromium: CVE-2021-37976 Information leak in core

*What is the version information for this release?* Microsoft Edge Version Date Released Based on Chromium Version 94.0.992.38 10/01/2021 94.0.4606.71

CVE-2021-37975: Chromium: CVE-2021-37975 Use after free in V8

*What is the version information for this release?* Microsoft Edge Version Date Released Based on Chromium Version 94.0.992.38 10/01/2021 94.0.4606.71

CVE-2021-37974: Chromium: CVE-2021-37974 Use after free in Safe Browsing

*What is the version information for this release?* Microsoft Edge Version Date Released Based on Chromium Version 94.0.992.38 10/01/2021 94.0.4606.71