Patch Tuesday Archive
Patch Tuesday August 2021
Total CVEs
45
Critical
7
Important
38
Exploited
1
Publicly Disclosed
3
All CVEs this month 45
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2021-33762 | Azure CycleCloud Elevation of Privilege Vulnerability | Important | 7 |
Azure | - | - | - |
| CVE-2021-34524 | Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability | Important | 8.1 |
Microsoft Dynamics | - | - | - |
| CVE-2021-34478 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2021-34480 | Scripting Engine Memory Corruption Vulnerability | Critical | 6.8 |
Microsoft Scripting Engine | - | - | - |
| CVE-2021-34534 | Windows MSHTML Platform Remote Code Execution Vulnerability | Critical | 6.8 |
Windows MSHTML Platform | - | - | - |
| CVE-2021-34486 | Windows Event Tracing Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Event Tracing | - | - | - |
| CVE-2021-34536 | Storage Spaces Controller Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Storage Spaces Controller | - | - | - |
| CVE-2021-34487 | Windows Event Tracing Elevation of Privilege Vulnerability | Important | 7 |
Windows Event Tracing | - | - | - |
| CVE-2021-34537 | Windows Bluetooth Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Bluetooth Service | - | - | - |
| CVE-2021-26423 | .NET Core and Visual Studio Denial of Service Vulnerability | Important | 7.5 |
.NET Core & Visual Studio | - | - | - |
| CVE-2021-26424 | Windows TCP/IP Remote Code Execution Vulnerability | Critical | 9.9 |
Windows TCP/IP | - | - | - |
| CVE-2021-26425 | Windows Event Tracing Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Event Tracing | - | - | - |
| CVE-2021-26426 | Windows User Account Profile Picture Elevation of Privilege Vulnerability | Important | 7 |
Windows User Profile Service | - | - | - |
| CVE-2021-26428 | Azure Sphere Information Disclosure Vulnerability | Important | 4.4 |
Azure Sphere | - | - | - |
| CVE-2021-26429 | Azure Sphere Elevation of Privilege Vulnerability | Important | 7.7 |
Azure Sphere | - | - | - |
| CVE-2021-26430 | Azure Sphere Denial of Service Vulnerability | Important | 6 |
Azure Sphere | - | - | - |
| CVE-2021-36936 | Windows Print Spooler Remote Code Execution Vulnerability | Critical | 8.8 |
Windows Print Spooler Components | - | Yes | - |
| CVE-2021-36937 | Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-36938 | Windows Cryptographic Primitives Library Information Disclosure Vulnerability | Important | 5.5 |
Windows Cryptographic Services | - | - | - |
| CVE-2021-36942 | Windows LSA Spoofing Vulnerability | Important | 7.5 |
Windows NTLM | - | Yes | - |
| CVE-2021-36940 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 7.6 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-36941 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2021-36945 | Windows 10 Update Assistant Elevation of Privilege Vulnerability | Important | 7.3 |
Windows Update Assistant | - | - | - |
| CVE-2021-36946 | Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2021-36947 | Windows Print Spooler Remote Code Execution Vulnerability | Important | 8.8 |
Windows Print Spooler Components | - | - | - |
| CVE-2021-36948 | Windows Update Medic Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Update | Yes | - | - |
| CVE-2021-36949 | Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability | Important | 7.1 |
Microsoft Azure Active Directory Connect | - | - | - |
| CVE-2021-36950 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2021-36958 | Windows Print Spooler Remote Code Execution Vulnerability | Important | 7.8 |
Windows Print Spooler Components | - | Yes | - |
| CVE-2021-34471 | Microsoft Windows Defender Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Defender | - | - | - |
| CVE-2021-34530 | Windows Graphics Component Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2021-34532 | ASP.NET Core and Visual Studio Information Disclosure Vulnerability | Important | 5.5 |
ASP.NET Core & Visual Studio | - | - | - |
| CVE-2021-34533 | Windows Graphics Component Font Parsing Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2021-34483 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Print Spooler Components | - | - | - |
| CVE-2021-34484 | Windows User Profile Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows User Profile Service | - | - | - |
| CVE-2021-34485 | .NET Core and Visual Studio Information Disclosure Vulnerability | Important | 5 |
.NET Core & Visual Studio | - | - | - |
| CVE-2021-34535 | Remote Desktop Client Remote Code Execution Vulnerability | Critical | 8.8 |
Remote Desktop Client | - | - | - |
| CVE-2021-26431 | Windows Recovery Environment Agent Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Update Assistant | - | - | - |
| CVE-2021-26432 | Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | Critical | 9.8 |
Windows Services for NFS ONCRPC XDR Driver | - | - | - |
| CVE-2021-26433 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | Important | 7.5 |
Windows Services for NFS ONCRPC XDR Driver | - | - | - |
| CVE-2021-36926 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | Important | 7.5 |
Windows Services for NFS ONCRPC XDR Driver | - | - | - |
| CVE-2021-36927 | Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Media | - | - | - |
| CVE-2021-36932 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | Important | 7.5 |
Windows Services for NFS ONCRPC XDR Driver | - | - | - |
| CVE-2021-36933 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | Important | 7.5 |
Windows Services for NFS ONCRPC XDR Driver | - | - | - |
| CVE-2021-36943 | Azure CycleCloud Elevation of Privilege Vulnerability | Important | 4 |
Azure | - | - | - |
Threat Categories 5
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 17 | - |
| Remote Code Execution | 14 | 7 |
| Information Disclosure | 8 | - |
| Spoofing | 4 | - |
| Denial of Service | 2 | - |
Affected Products 27
| Product | CVEs | Exploited |
|---|---|---|
| Windows Services for NFS ONCRPC XDR Driver | 5 | - |
| Windows Print Spooler Components | 4 | - |
| Azure Sphere | 3 | - |
| Microsoft Dynamics | 3 | - |
| Windows Event Tracing | 3 | - |
| .NET Core & Visual Studio | 2 | - |
| Azure | 2 | - |
| Microsoft Graphics Component | 2 | - |
| Windows Update Assistant | 2 | - |
| Windows User Profile Service | 2 | - |
| ASP.NET Core & Visual Studio | 1 | - |
| Microsoft Azure Active Directory Connect | 1 | - |
| Microsoft Office | 1 | - |
| Microsoft Office SharePoint | 1 | - |
| Microsoft Office Word | 1 | - |
| Microsoft Scripting Engine | 1 | - |
| Microsoft Windows Codecs Library | 1 | - |
| Remote Desktop Client | 1 | - |
| Windows Bluetooth Service | 1 | - |
| Windows Cryptographic Services | 1 | - |
| Windows Defender | 1 | - |
| Windows MSHTML Platform | 1 | - |
| Windows Media | 1 | - |
| Windows NTLM | 1 | - |
| Windows Storage Spaces Controller | 1 | - |
| Windows TCP/IP | 1 | - |
| Windows Update | 1 | 1 |