Patch Tuesday Archive
Patch Tuesday November 2021
Total CVEs
60
Critical
5
Important
53
Exploited
2
Publicly Disclosed
5
All CVEs this month 60
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2021-36957 | Windows Desktop Bridge Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Desktop Bridge | - | - | - |
| CVE-2021-41366 | Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Cred SSProvider Protocol | - | - | - |
| CVE-2021-41367 | NTFS Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NTFS | - | - | - |
| CVE-2021-41368 | Microsoft Access Remote Code Execution Vulnerability | Important | 6.1 |
Microsoft Office Access | - | - | - |
| CVE-2021-41371 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | Important | 4.4 |
Windows RDP | - | Yes | - |
| CVE-2021-41372 | Power BI Report Server Spoofing Vulnerability | Important | 7.6 |
Power BI | - | - | - |
| CVE-2021-41377 | Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Fast FAT Driver | - | - | - |
| CVE-2021-41378 | Windows NTFS Remote Code Execution Vulnerability | Important | 7.8 |
Windows NTFS | - | - | - |
| CVE-2021-41379 | Windows Installer Elevation of Privilege Vulnerability | Important | 5.5 |
Windows Installer | - | - | - |
| CVE-2021-26443 | Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability | Critical | 9 |
Windows Virtual Machine Bus | - | - | - |
| CVE-2021-42274 | Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability | Important | 6.8 |
Role: Windows Hyper-V | - | - | - |
| CVE-2021-42275 | Microsoft COM for Windows Remote Code Execution Vulnerability | Important | 8.8 |
Windows COM | - | - | - |
| CVE-2021-42276 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-42279 | Chakra Scripting Engine Memory Corruption Vulnerability | Critical | 4.2 |
Windows Scripting | - | - | - |
| CVE-2021-42280 | Windows Feedback Hub Elevation of Privilege Vulnerability | Important | 5.5 |
Windows Feedback Hub | - | - | - |
| CVE-2021-42300 | Azure Sphere Tampering Vulnerability | Important | 6 |
Azure Sphere | - | - | - |
| CVE-2021-42301 | Azure RTOS Information Disclosure Vulnerability | Important | 3.3 |
Azure Real Time Operating System | - | - | - |
| CVE-2021-42302 | Azure RTOS Elevation of Privilege Vulnerability | Important | 6.6 |
Azure Real Time Operating System | - | - | - |
| CVE-2021-42303 | Azure RTOS Elevation of Privilege Vulnerability | Important | 6.6 |
Azure Real Time Operating System | - | - | - |
| CVE-2021-42304 | Azure RTOS Elevation of Privilege Vulnerability | Important | 6.6 |
Azure Real Time Operating System | - | - | - |
| CVE-2021-42316 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Dynamics | - | - | - |
| CVE-2021-42319 | Visual Studio Elevation of Privilege Vulnerability | Important | 4.7 |
Visual Studio | - | - | - |
| CVE-2021-42322 | Visual Studio Code Elevation of Privilege Vulnerability | Important | 7.8 |
Visual Studio Code | - | - | - |
| CVE-2021-43208 | 3D Viewer Remote Code Execution Vulnerability | Important | 7.8 |
3D Viewer | - | Yes | - |
| CVE-2021-43209 | 3D Viewer Remote Code Execution Vulnerability | Important | 7.8 |
3D Viewer | - | Yes | - |
| CVE-2021-42321 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Exchange Server | Yes | - | - |
| CVE-2021-43211 | Windows 10 Update Assistant Elevation of Privilege Vulnerability | Important | 5.5 |
Windows Update Assistant | - | Yes | - |
| CVE-2021-42297 | Windows 10 Update Assistant Elevation of Privilege Vulnerability | Important | 5 |
Windows Update Assistant | - | - | - |
| CVE-2021-43220 | Microsoft Edge for iOS Spoofing Vulnerability | Moderate | 3.1 |
Microsoft Edge for iOS | - | - | - |
| CVE-2021-42308 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Low | 3.1 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2021-43221 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Important | 4.2 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2021-38665 | Remote Desktop Protocol Client Information Disclosure Vulnerability | Important | 7.4 |
Windows RDP | - | - | - |
| CVE-2021-38666 | Remote Desktop Client Remote Code Execution Vulnerability | Critical | 8.8 |
Windows RDP | - | - | - |
| CVE-2021-40442 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2021-38631 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | Important | 4.4 |
Windows RDP | - | Yes | - |
| CVE-2021-41351 | Microsoft Edge (Chrome based) Spoofing on IE Mode | Important | 4.3 |
Microsoft Edge (Chromium-based) in IE Mode | - | - | - |
| CVE-2021-41349 | Microsoft Exchange Server Spoofing Vulnerability | Important | 6.5 |
Microsoft Exchange Server | - | - | - |
| CVE-2021-41370 | NTFS Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NTFS | - | - | - |
| CVE-2021-41373 | FSLogix Information Disclosure Vulnerability | Important | 5.5 |
Azure | - | - | - |
| CVE-2021-41374 | Azure Sphere Information Disclosure Vulnerability | Important | 6.7 |
Azure Sphere | - | - | - |
| CVE-2021-41375 | Azure Sphere Information Disclosure Vulnerability | Important | 4.4 |
Azure Sphere | - | - | - |
| CVE-2021-41376 | Azure Sphere Information Disclosure Vulnerability | Important | 2.3 |
Azure Sphere | - | - | - |
| CVE-2021-42277 | Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability | Important | 5.5 |
Windows Diagnostic Hub | - | - | - |
| CVE-2021-42282 | Active Directory Domain Services Elevation of Privilege Vulnerability | Important | 7.5 |
Windows Active Directory | - | - | - |
| CVE-2021-42283 | NTFS Elevation of Privilege Vulnerability | Important | 8.8 |
Windows NTFS | - | - | - |
| CVE-2021-42284 | Windows Hyper-V Denial of Service Vulnerability | Important | 6.8 |
Role: Windows Hyper-V | - | - | - |
| CVE-2021-42285 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2021-42286 | Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Core Shell | - | - | - |
| CVE-2021-42287 | Active Directory Domain Services Elevation of Privilege Vulnerability | Important | 7.5 |
Windows Active Directory | - | - | - |
| CVE-2021-42288 | Windows Hello Security Feature Bypass Vulnerability | Important | 5.7 |
Windows Hello | - | - | - |
| CVE-2021-42291 | Active Directory Domain Services Elevation of Privilege Vulnerability | Important | 7.5 |
Windows Active Directory | - | - | - |
| CVE-2021-42292 | Microsoft Excel Security Feature Bypass Vulnerability | Important | 7.8 |
Microsoft Office Excel | Yes | - | - |
| CVE-2021-42296 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2021-42298 | Microsoft Defender Remote Code Execution Vulnerability | Critical | 7.8 |
Windows Defender | - | - | - |
| CVE-2021-42305 | Microsoft Exchange Server Spoofing Vulnerability | Important | 6.5 |
Microsoft Exchange Server | - | - | - |
| CVE-2021-41356 | Windows Denial of Service Vulnerability | Important | 7.5 |
Microsoft Windows | - | - | - |
| CVE-2021-42278 | Active Directory Domain Services Elevation of Privilege Vulnerability | Important | 7.5 |
Windows Active Directory | - | - | - |
| CVE-2021-42323 | Azure RTOS Information Disclosure Vulnerability | Important | 3.3 |
Azure Real Time Operating System | - | - | - |
| CVE-2021-26444 | Azure RTOS Information Disclosure Vulnerability | Important | 3.3 |
Azure Real Time Operating System | - | - | - |
| CVE-2021-42306 | Azure Active Directory Information Disclosure Vulnerability | Important | 8.1 |
Azure | - | - | - |
Threat Categories 7
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 22 | - |
| Remote Code Execution | 15 | 5 |
| Information Disclosure | 11 | - |
| Spoofing | 6 | - |
| Denial of Service | 3 | - |
| Security Feature Bypass | 2 | - |
| Tampering | 1 | - |
Affected Products 35
| Product | CVEs | Exploited |
|---|---|---|
| Azure Real Time Operating System | 6 | - |
| Azure Sphere | 4 | - |
| Windows Active Directory | 4 | - |
| Windows NTFS | 4 | - |
| Windows RDP | 4 | - |
| Microsoft Exchange Server | 3 | 1 |
| 3D Viewer | 2 | - |
| Azure | 2 | - |
| Microsoft Edge (Chromium-based) | 2 | - |
| Microsoft Office Excel | 2 | 1 |
| Role: Windows Hyper-V | 2 | - |
| Windows Update Assistant | 2 | - |
| Microsoft Dynamics | 1 | - |
| Microsoft Edge (Chromium-based) in IE Mode | 1 | - |
| Microsoft Edge for iOS | 1 | - |
| Microsoft Office Access | 1 | - |
| Microsoft Office Word | 1 | - |
| Microsoft Windows | 1 | - |
| Microsoft Windows Codecs Library | 1 | - |
| Power BI | 1 | - |
| Visual Studio | 1 | - |
| Visual Studio Code | 1 | - |
| Windows COM | 1 | - |
| Windows Core Shell | 1 | - |
| Windows Cred SSProvider Protocol | 1 | - |
| Windows Defender | 1 | - |
| Windows Desktop Bridge | 1 | - |
| Windows Diagnostic Hub | 1 | - |
| Windows Fast FAT Driver | 1 | - |
| Windows Feedback Hub | 1 | - |
| Windows Hello | 1 | - |
| Windows Installer | 1 | - |
| Windows Kernel | 1 | - |
| Windows Scripting | 1 | - |
| Windows Virtual Machine Bus | 1 | - |