Patch Tuesday Archive
Patch Tuesday May 2021
Total CVEs
54
Critical
4
Important
49
Exploited
0
Publicly Disclosed
3
All CVEs this month 54
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2021-27068 | Visual Studio Remote Code Execution Vulnerability | Important | 8.8 |
Visual Studio | - | - | - |
| CVE-2021-28455 | Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability | Important | 8.8 |
Jet Red and Access Connectivity | - | - | - |
| CVE-2021-28461 | Dynamics Finance and Operations Cross-site Scripting Vulnerability | Important | 6.1 |
Microsoft Dynamics Finance & Operations | - | - | - |
| CVE-2021-28479 | Windows CSC Service Information Disclosure Vulnerability | Important | 5.5 |
Windows CSC Service | - | - | - |
| CVE-2021-26419 | Scripting Engine Memory Corruption Vulnerability | Critical | 7.5 |
Internet Explorer | - | - | - |
| CVE-2021-31165 | Windows Container Manager Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Container Manager Service | - | - | - |
| CVE-2021-31166 | HTTP Protocol Stack Remote Code Execution Vulnerability | Critical | 9.8 |
Windows HTTP.sys | - | - | - |
| CVE-2021-31167 | Windows Container Manager Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Container Manager Service | - | - | - |
| CVE-2021-31168 | Windows Container Manager Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Container Manager Service | - | - | - |
| CVE-2021-31169 | Windows Container Manager Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Container Manager Service | - | - | - |
| CVE-2021-31170 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2021-31171 | Microsoft SharePoint Information Disclosure Vulnerability | Important | 4.1 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-31172 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 7.1 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-31173 | Microsoft SharePoint Server Information Disclosure Vulnerability | Important | 5.3 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-31174 | Microsoft Excel Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Office Excel | - | - | - |
| CVE-2021-31175 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2021-31176 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2021-31177 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2021-31178 | Microsoft Office Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Office Excel | - | - | - |
| CVE-2021-31179 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2021-31180 | Microsoft Office Graphics Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2021-31181 | Microsoft SharePoint Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-31182 | Microsoft Bluetooth Driver Spoofing Vulnerability | Important | 7.1 |
Microsoft Bluetooth Driver | - | - | - |
| CVE-2021-31184 | Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows IrDA | - | - | - |
| CVE-2021-31185 | Windows Desktop Bridge Denial of Service Vulnerability | Important | 5.5 |
Windows Desktop Bridge | - | - | - |
| CVE-2021-31186 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | Important | 7.4 |
Windows RDP Client | - | - | - |
| CVE-2021-31187 | Windows WalletService Elevation of Privilege Vulnerability | Important | 7.8 |
Windows WalletService | - | - | - |
| CVE-2021-31188 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2021-31190 | Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Container Isolation FS Filter Driver | - | - | - |
| CVE-2021-31191 | Windows Projected File System FS Filter Driver Information Disclosure Vulnerability | Important | 5.5 |
Windows Projected File System FS Filter | - | - | - |
| CVE-2021-31192 | Windows Media Foundation Core Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-31193 | Windows SSDP Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows SSDP Service | - | - | - |
| CVE-2021-31194 | OLE Automation Remote Code Execution Vulnerability | Critical | 8.8 |
Windows OLE | - | - | - |
| CVE-2021-31195 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 6.5 |
Microsoft Exchange Server | - | - | - |
| CVE-2021-31198 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Exchange Server | - | - | - |
| CVE-2021-31204 | .NET and Visual Studio Elevation of Privilege Vulnerability | Important | 7.3 |
.NET Core & Visual Studio | - | Yes | - |
| CVE-2021-31205 | Windows SMB Client Security Feature Bypass Vulnerability | Important | 6.5 |
Windows SMB | - | - | - |
| CVE-2021-31207 | Microsoft Exchange Server Security Feature Bypass Vulnerability | Moderate | 6.6 |
Microsoft Exchange Server | - | Yes | - |
| CVE-2021-31208 | Windows Container Manager Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Container Manager Service | - | - | - |
| CVE-2021-31209 | Microsoft Exchange Server Spoofing Vulnerability | Important | 6.5 |
Microsoft Exchange Server | - | - | - |
| CVE-2021-31211 | Visual Studio Code Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio Code | - | - | - |
| CVE-2021-31213 | Visual Studio Code Remote Containers Extension Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio Code | - | - | - |
| CVE-2021-31214 | Visual Studio Code Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio Code | - | - | - |
| CVE-2021-26421 | Skype for Business and Lync Spoofing Vulnerability | Important | 6.5 |
Skype for Business and Microsoft Lync | - | - | - |
| CVE-2021-26422 | Skype for Business and Lync Remote Code Execution Vulnerability | Important | 7.2 |
Skype for Business and Microsoft Lync | - | - | - |
| CVE-2021-28465 | Web Media Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-28474 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-28476 | Windows Hyper-V Remote Code Execution Vulnerability | Critical | 9.9 |
Role: Windows Hyper-V | - | - | - |
| CVE-2021-28478 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 7.6 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-26418 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 4.6 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-31200 | Common Utilities Remote Code Execution Vulnerability | Important | 7.2 |
Open Source Software | - | Yes | - |
| CVE-2021-31936 | Microsoft Accessibility Insights for Web Information Disclosure Vulnerability | Important | 7.4 |
Microsoft Accessibility Insights for Web | - | - | - |
| CVE-2021-31937 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 8.2 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2021-31982 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | Important | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - |
Threat Categories 6
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 22 | 4 |
| Elevation of Privilege | 12 | - |
| Information Disclosure | 9 | - |
| Spoofing | 7 | - |
| Security Feature Bypass | 3 | - |
| Denial of Service | 1 | - |
Affected Products 31
| Product | CVEs | Exploited |
|---|---|---|
| Microsoft Office SharePoint | 7 | - |
| Microsoft Office Excel | 5 | - |
| Windows Container Manager Service | 5 | - |
| Microsoft Exchange Server | 4 | - |
| Visual Studio Code | 3 | - |
| Microsoft Edge (Chromium-based) | 2 | - |
| Microsoft Graphics Component | 2 | - |
| Microsoft Windows Codecs Library | 2 | - |
| Skype for Business and Microsoft Lync | 2 | - |
| .NET Core & Visual Studio | 1 | - |
| Internet Explorer | 1 | - |
| Jet Red and Access Connectivity | 1 | - |
| Microsoft Accessibility Insights for Web | 1 | - |
| Microsoft Bluetooth Driver | 1 | - |
| Microsoft Dynamics Finance & Operations | 1 | - |
| Microsoft Office | 1 | - |
| Microsoft Office Word | 1 | - |
| Microsoft Windows IrDA | 1 | - |
| Open Source Software | 1 | - |
| Role: Windows Hyper-V | 1 | - |
| Visual Studio | 1 | - |
| Windows CSC Service | 1 | - |
| Windows Container Isolation FS Filter Driver | 1 | - |
| Windows Desktop Bridge | 1 | - |
| Windows HTTP.sys | 1 | - |
| Windows OLE | 1 | - |
| Windows Projected File System FS Filter | 1 | - |
| Windows RDP Client | 1 | - |
| Windows SMB | 1 | - |
| Windows SSDP Service | 1 | - |
| Windows WalletService | 1 | - |