Patch Tuesday Archive
Patch Tuesday September 2021
Total CVEs
66
Critical
3
Important
62
Exploited
1
Publicly Disclosed
2
All CVEs this month 66
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2021-36952 | Visual Studio Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio | - | - | - |
| CVE-2021-36954 | Windows Bind Filter Driver Elevation of Privilege Vulnerability | Important | 8.8 |
Windows Bind Filter Driver | - | - | - |
| CVE-2021-36955 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | Yes |
| CVE-2021-36959 | Windows Authenticode Spoofing Vulnerability | Important | 5.5 |
Windows Authenticode | - | - | - |
| CVE-2021-36960 | Windows SMB Information Disclosure Vulnerability | Important | 7.5 |
Windows SMB | - | - | - |
| CVE-2021-36961 | Windows Installer Denial of Service Vulnerability | Important | 5.5 |
Windows Installer | - | - | - |
| CVE-2021-36962 | Windows Installer Information Disclosure Vulnerability | Important | 5.5 |
Windows Installer | - | - | - |
| CVE-2021-36963 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2021-36964 | Windows Event Tracing Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Event Tracing | - | - | - |
| CVE-2021-36965 | Windows WLAN AutoConfig Service Remote Code Execution Vulnerability | Critical | 8.8 |
Windows WLAN Auto Config Service | - | - | - |
| CVE-2021-36966 | Windows Subsystem for Linux Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Subsystem for Linux | - | - | - |
| CVE-2021-36967 | Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability | Important | 8 |
Windows WLAN Service | - | - | - |
| CVE-2021-36968 | Windows DNS Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows DNS | - | Yes | - |
| CVE-2021-36969 | Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability | Important | 5.5 |
Windows Redirected Drive Buffering | - | - | - |
| CVE-2021-36972 | Windows SMB Information Disclosure Vulnerability | Important | 5.5 |
Windows SMB | - | - | - |
| CVE-2021-36973 | Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Redirected Drive Buffering | - | - | - |
| CVE-2021-36974 | Windows SMB Elevation of Privilege Vulnerability | Important | 7.8 |
Windows SMB | - | - | - |
| CVE-2021-36975 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K | - | - | - |
| CVE-2021-26435 | Windows Scripting Engine Memory Corruption Vulnerability | Critical | 8.1 |
Windows Scripting | - | - | - |
| CVE-2021-26436 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 6.1 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2021-38624 | Windows Key Storage Provider Security Feature Bypass Vulnerability | Important | 6.5 |
Windows Key Storage Provider | - | - | - |
| CVE-2021-38625 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2021-38626 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2021-38628 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2021-38629 | Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability | Important | 6.5 |
Windows TDX.sys | - | - | - |
| CVE-2021-38630 | Windows Event Tracing Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Event Tracing | - | - | - |
| CVE-2021-38632 | BitLocker Security Feature Bypass Vulnerability | Important | 5.7 |
Windows BitLocker | - | - | - |
| CVE-2021-38633 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2021-38634 | Microsoft Windows Update Client Elevation of Privilege Vulnerability | Important | 7.1 |
Windows Update | - | - | - |
| CVE-2021-38635 | Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability | Important | 5.5 |
Windows Redirected Drive Buffering | - | - | - |
| CVE-2021-38636 | Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability | Important | 5.5 |
Windows Redirected Drive Buffering | - | - | - |
| CVE-2021-38637 | Windows Storage Information Disclosure Vulnerability | Important | 5.5 |
Windows Storage | - | - | - |
| CVE-2021-38638 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2021-38641 | Microsoft Edge for Android Spoofing Vulnerability | Important | 6.1 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2021-38642 | Microsoft Edge for iOS Spoofing Vulnerability | Important | 6.1 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2021-38645 | Open Management Infrastructure Elevation of Privilege Vulnerability | Important | 7.8 |
Azure Open Management Infrastructure | - | - | - |
| CVE-2021-38647 | Open Management Infrastructure Remote Code Execution Vulnerability | Critical | 9.8 |
Azure Open Management Infrastructure | - | - | - |
| CVE-2021-38648 | Open Management Infrastructure Elevation of Privilege Vulnerability | Important | 7.8 |
Azure Open Management Infrastructure | - | - | - |
| CVE-2021-38649 | Open Management Infrastructure Elevation of Privilege Vulnerability | Important | 7 |
Azure Open Management Infrastructure | - | - | - |
| CVE-2021-38669 | Microsoft Edge (Chromium-based) Tampering Vulnerability | Important | 6.4 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2021-26437 | Visual Studio Code Spoofing Vulnerability | Important | 5.5 |
Visual Studio | - | - | - |
| CVE-2021-26439 | Microsoft Edge for Android Information Disclosure Vulnerability | Moderate | 4.6 |
Microsoft Edge for Android | - | - | - |
| CVE-2021-40440 | Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | Important | 5.4 |
Dynamics Business Central Control | - | - | - |
| CVE-2021-40444 | Microsoft MSHTML Remote Code Execution Vulnerability | Important | 8.8 |
Windows MSHTML Platform | Yes | Yes | - |
| CVE-2021-36930 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 5.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2021-36956 | Azure Sphere Information Disclosure Vulnerability | Important | 4.4 |
Azure Sphere | - | - | - |
| CVE-2021-26434 | Visual Studio Elevation of Privilege Vulnerability | Important | 7.8 |
Visual Studio | - | - | - |
| CVE-2021-38639 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K | - | - | - |
| CVE-2021-38644 | Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft MPEG-2 Video Extension | - | - | - |
| CVE-2021-38646 | Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Access | - | - | - |
| CVE-2021-38650 | Microsoft Office Spoofing Vulnerability | Important | 7.6 |
Microsoft Office | - | - | - |
| CVE-2021-38651 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 7.6 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-38652 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 7.6 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-38653 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2021-38654 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2021-38655 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2021-38656 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2021-38657 | Microsoft Office Graphics Component Information Disclosure Vulnerability | Important | 6.1 |
Microsoft Office | - | - | - |
| CVE-2021-38658 | Microsoft Office Graphics Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2021-38659 | Microsoft Office Graphics Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2021-38660 | Microsoft Office Graphics Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2021-38661 | HEVC Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-38667 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Print Spooler Components | - | - | - |
| CVE-2021-38671 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Print Spooler Components | - | - | - |
| CVE-2021-40447 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Print Spooler Components | - | - | - |
| CVE-2021-40448 | Microsoft Accessibility Insights for Android Information Disclosure Vulnerability | Important | 6.3 |
Microsoft Accessibility Insights for Android | - | - | - |
Threat Categories 7
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 27 | - |
| Remote Code Execution | 16 | 3 |
| Information Disclosure | 11 | - |
| Spoofing | 8 | - |
| Security Feature Bypass | 2 | - |
| Denial of Service | 1 | - |
| Tampering | 1 | - |
Affected Products 37
| Product | CVEs | Exploited |
|---|---|---|
| Microsoft Edge (Chromium-based) | 5 | - |
| Azure Open Management Infrastructure | 4 | - |
| Microsoft Office | 4 | - |
| Windows Redirected Drive Buffering | 4 | - |
| Visual Studio | 3 | - |
| Windows Common Log File System Driver | 3 | - |
| Windows Print Spooler Components | 3 | - |
| Windows SMB | 3 | - |
| Microsoft Office Excel | 2 | - |
| Microsoft Office SharePoint | 2 | - |
| Microsoft Office Visio | 2 | - |
| Windows Ancillary Function Driver for WinSock | 2 | - |
| Windows Event Tracing | 2 | - |
| Windows Installer | 2 | - |
| Windows Kernel | 2 | - |
| Windows Win32K | 2 | - |
| Azure Sphere | 1 | - |
| Dynamics Business Central Control | 1 | - |
| Microsoft Accessibility Insights for Android | 1 | - |
| Microsoft Edge for Android | 1 | - |
| Microsoft MPEG-2 Video Extension | 1 | - |
| Microsoft Office Access | 1 | - |
| Microsoft Office Word | 1 | - |
| Microsoft Windows Codecs Library | 1 | - |
| Microsoft Windows DNS | 1 | - |
| Windows Authenticode | 1 | - |
| Windows Bind Filter Driver | 1 | - |
| Windows BitLocker | 1 | - |
| Windows Key Storage Provider | 1 | - |
| Windows MSHTML Platform | 1 | 1 |
| Windows Scripting | 1 | - |
| Windows Storage | 1 | - |
| Windows Subsystem for Linux | 1 | - |
| Windows TDX.sys | 1 | - |
| Windows Update | 1 | - |
| Windows WLAN Auto Config Service | 1 | - |
| Windows WLAN Service | 1 | - |