Patch Tuesday Archive
Patch Tuesday April 2021
Total CVEs
108
Critical
19
Important
88
Exploited
1
Publicly Disclosed
4
All CVEs this month 108
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2021-27067 | Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability | Important | 6.5 |
Azure DevOps | - | - | - |
| CVE-2021-27072 | Win32k Elevation of Privilege Vulnerability | Important | 7 |
Windows Win32K | - | - | - |
| CVE-2021-27079 | Windows Media Photo Codec Information Disclosure Vulnerability | Important | 5.7 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-27088 | Windows Event Tracing Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Event Tracing | - | - | - |
| CVE-2021-27089 | Microsoft Internet Messaging API Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Internet Messaging API | - | - | - |
| CVE-2021-27090 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Secure Kernel Mode | - | - | - |
| CVE-2021-27091 | RPC Endpoint Mapper Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Registry | - | Yes | - |
| CVE-2021-27092 | Azure AD Web Sign-in Security Feature Bypass Vulnerability | Important | 6.8 |
Azure AD Web Sign-in | - | - | - |
| CVE-2021-27093 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2021-27094 | Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability | Important | 4.4 |
Windows ELAM | - | - | - |
| CVE-2021-27095 | Windows Media Video Decoder Remote Code Execution Vulnerability | Critical | 7.8 |
Windows Media Player | - | - | - |
| CVE-2021-27096 | NTFS Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NTFS | - | - | - |
| CVE-2021-26413 | Windows Installer Spoofing Vulnerability | Important | 6.2 |
Windows Installer | - | - | - |
| CVE-2021-26415 | Windows Installer Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Installer | - | - | - |
| CVE-2021-26416 | Windows Hyper-V Denial of Service Vulnerability | Important | 7.7 |
Role: Windows Hyper-V | - | - | - |
| CVE-2021-26417 | Windows Overlay Filter Information Disclosure Vulnerability | Important | 5.5 |
Windows Overlay Filter | - | - | - |
| CVE-2021-28309 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2021-28310 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K | Yes | - | - |
| CVE-2021-28311 | Windows Application Compatibility Cache Denial of Service Vulnerability | Important | 6.5 |
Windows Application Compatibility Cache | - | - | - |
| CVE-2021-28312 | Windows NTFS Denial of Service Vulnerability | Moderate | 3.3 |
Windows NTFS | - | Yes | - |
| CVE-2021-28313 | Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Diagnostic Hub | - | - | - |
| CVE-2021-28314 | Windows Hyper-V Elevation of Privilege Vulnerability | Important | 7.8 |
Role: Windows Hyper-V | - | - | - |
| CVE-2021-28315 | Windows Media Video Decoder Remote Code Execution Vulnerability | Critical | 7.8 |
Windows Media Player | - | - | - |
| CVE-2021-28316 | Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability | Important | 4.2 |
Windows WLAN Auto Config Service | - | - | - |
| CVE-2021-28317 | Microsoft Windows Codecs Library Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-28318 | Windows GDI+ Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2021-28319 | Windows TCP/IP Driver Denial of Service Vulnerability | Important | 7.5 |
Windows TCP/IP | - | - | - |
| CVE-2021-28320 | Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Resource Manager | - | - | - |
| CVE-2021-28321 | Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Diagnostic Hub | - | - | - |
| CVE-2021-28322 | Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Diagnostic Hub | - | - | - |
| CVE-2021-28323 | Windows DNS Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Windows DNS | - | - | - |
| CVE-2021-28324 | Windows SMB Information Disclosure Vulnerability | Important | 7.5 |
Windows SMB Server | - | - | - |
| CVE-2021-28325 | Windows SMB Information Disclosure Vulnerability | Important | 6.5 |
Windows SMB Server | - | - | - |
| CVE-2021-28326 | Windows AppX Deployment Server Denial of Service Vulnerability | Important | 5.5 |
Windows AppX Deployment Extensions | - | - | - |
| CVE-2021-28327 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28328 | Windows DNS Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Windows DNS | - | - | - |
| CVE-2021-28329 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Critical | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28330 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Critical | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28331 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Critical | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28332 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Critical | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28333 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Critical | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28334 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Critical | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28335 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Critical | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28336 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Critical | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28337 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Critical | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28338 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Critical | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28339 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Critical | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28340 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28341 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28342 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28343 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Critical | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28344 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28345 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28346 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28347 | Windows Speech Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows Speech | - | - | - |
| CVE-2021-28348 | Windows GDI+ Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2021-28349 | Windows GDI+ Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2021-28350 | Windows GDI+ Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2021-28351 | Windows Speech Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows Speech | - | - | - |
| CVE-2021-28352 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28353 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28354 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28355 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28356 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28357 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28358 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28434 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2021-28435 | Windows Event Tracing Information Disclosure Vulnerability | Important | 5.5 |
Windows Event Tracing | - | - | - |
| CVE-2021-28436 | Windows Speech Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows Speech | - | - | - |
| CVE-2021-28437 | Windows Installer Information Disclosure Vulnerability | Important | 5.5 |
Windows Installer | - | Yes | - |
| CVE-2021-28438 | Windows Console Driver Denial of Service Vulnerability | Important | 5.5 |
Windows Console Driver | - | - | - |
| CVE-2021-28439 | Windows TCP/IP Driver Denial of Service Vulnerability | Important | 7.5 |
Windows TCP/IP | - | - | - |
| CVE-2021-28440 | Windows Installer Elevation of Privilege Vulnerability | Important | 7 |
Windows Installer | - | - | - |
| CVE-2021-28441 | Windows Hyper-V Information Disclosure Vulnerability | Important | 6.5 |
Role: Windows Hyper-V | - | - | - |
| CVE-2021-28442 | Windows TCP/IP Information Disclosure Vulnerability | Important | 6.5 |
Windows TCP/IP | - | - | - |
| CVE-2021-28443 | Windows Console Driver Denial of Service Vulnerability | Important | 5.5 |
Windows Console Driver | - | - | - |
| CVE-2021-28444 | Windows Hyper-V Security Feature Bypass Vulnerability | Important | 5.7 |
Role: Windows Hyper-V | - | - | - |
| CVE-2021-28445 | Windows Network File System Remote Code Execution Vulnerability | Important | 8.1 |
Windows Network File System | - | - | - |
| CVE-2021-28446 | Windows Portmapping Information Disclosure Vulnerability | Important | 7.1 |
Windows Portmapping | - | - | - |
| CVE-2021-28447 | Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability | Important | 4.4 |
Windows Early Launch Antimalware Driver | - | - | - |
| CVE-2021-28448 | Visual Studio Code Kubernetes Tools Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio Code - Kubernetes Tools | - | - | - |
| CVE-2021-28449 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2021-28450 | Microsoft SharePoint Denial of Service Update | Important | 5 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-28451 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2021-28452 | Microsoft Outlook Memory Corruption Vulnerability | Important | 7.1 |
Microsoft Office Outlook | - | - | - |
| CVE-2021-28453 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2021-28454 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2021-28456 | Microsoft Excel Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Office Excel | - | - | - |
| CVE-2021-28457 | Visual Studio Code Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio Code | - | - | - |
| CVE-2021-28458 | Azure ms-rest-nodeauth Library Elevation of Privilege Vulnerability | Important | 7.8 |
Open Source Software | - | Yes | - |
| CVE-2021-28459 | Azure DevOps Server Spoofing Vulnerability | Important | 6.1 |
Azure DevOps | - | - | - |
| CVE-2021-28460 | Azure Sphere Unsigned Code Execution Vulnerability | Critical | 8.1 |
Azure Sphere | - | - | - |
| CVE-2021-28469 | Visual Studio Code Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio Code | - | - | - |
| CVE-2021-28470 | Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio Code - GitHub Pull Requests and Issues Extension | - | - | - |
| CVE-2021-28471 | Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio Code | - | - | - |
| CVE-2021-28472 | Visual Studio Code Maven for Java Extension Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio Code - Maven for Java Extension | - | - | - |
| CVE-2021-28475 | Visual Studio Code Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio Code | - | - | - |
| CVE-2021-28477 | Visual Studio Code Remote Code Execution Vulnerability | Important | 7 |
Visual Studio Code | - | - | - |
| CVE-2021-28480 | Microsoft Exchange Server Remote Code Execution Vulnerability | Critical | 9.8 |
Microsoft Exchange Server | - | - | - |
| CVE-2021-28481 | Microsoft Exchange Server Remote Code Execution Vulnerability | Critical | 9.8 |
Microsoft Exchange Server | - | - | - |
| CVE-2021-28482 | Microsoft Exchange Server Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Exchange Server | - | - | - |
| CVE-2021-28483 | Microsoft Exchange Server Remote Code Execution Vulnerability | Critical | 9 |
Microsoft Exchange Server | - | - | - |
| CVE-2021-27064 | Visual Studio Installer Elevation of Privilege Vulnerability | Important | 7.8 |
Visual Studio | - | - | - |
| CVE-2021-27086 | Windows Services and Controller App Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Services and Controller App | - | - | - |
| CVE-2021-28464 | VP9 Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-28466 | Raw Image Extension Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-28468 | Raw Image Extension Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-28473 | Visual Studio Code Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio Code | - | - | - |
Threat Categories 6
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 56 | 19 |
| Elevation of Privilege | 19 | - |
| Information Disclosure | 17 | - |
| Denial of Service | 9 | - |
| Security Feature Bypass | 5 | - |
| Spoofing | 2 | - |
Affected Products 43
| Product | CVEs | Exploited |
|---|---|---|
| Windows Remote Procedure Call Runtime | 27 | - |
| Visual Studio Code | 6 | - |
| Microsoft Windows Codecs Library | 5 | - |
| Microsoft Exchange Server | 4 | - |
| Microsoft Graphics Component | 4 | - |
| Microsoft Office Excel | 4 | - |
| Role: Windows Hyper-V | 4 | - |
| Windows Installer | 4 | - |
| Microsoft Windows Speech | 3 | - |
| Windows Diagnostic Hub | 3 | - |
| Windows TCP/IP | 3 | - |
| Azure DevOps | 2 | - |
| Microsoft Windows DNS | 2 | - |
| Windows Console Driver | 2 | - |
| Windows Event Tracing | 2 | - |
| Windows Kernel | 2 | - |
| Windows Media Player | 2 | - |
| Windows NTFS | 2 | - |
| Windows SMB Server | 2 | - |
| Windows Win32K | 2 | 1 |
| Azure AD Web Sign-in | 1 | - |
| Azure Sphere | 1 | - |
| Microsoft Internet Messaging API | 1 | - |
| Microsoft Office Outlook | 1 | - |
| Microsoft Office SharePoint | 1 | - |
| Microsoft Office Word | 1 | - |
| Open Source Software | 1 | - |
| Visual Studio | 1 | - |
| Visual Studio Code - GitHub Pull Requests and Issues Extension | 1 | - |
| Visual Studio Code - Kubernetes Tools | 1 | - |
| Visual Studio Code - Maven for Java Extension | 1 | - |
| Windows AppX Deployment Extensions | 1 | - |
| Windows Application Compatibility Cache | 1 | - |
| Windows ELAM | 1 | - |
| Windows Early Launch Antimalware Driver | 1 | - |
| Windows Network File System | 1 | - |
| Windows Overlay Filter | 1 | - |
| Windows Portmapping | 1 | - |
| Windows Registry | 1 | - |
| Windows Resource Manager | 1 | - |
| Windows Secure Kernel Mode | 1 | - |
| Windows Services and Controller App | 1 | - |
| Windows WLAN Auto Config Service | 1 | - |