Patch Tuesday Archive
Patch Tuesday December 2021
Total CVEs
68
Critical
7
Important
61
Exploited
1
Publicly Disclosed
6
All CVEs this month 68
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2021-40441 | Windows Media Center Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Media | - | - | - |
| CVE-2021-42310 | Microsoft Defender for IoT Remote Code Execution Vulnerability | Critical | 9.8 |
Microsoft Defender for IoT | - | - | - |
| CVE-2021-42311 | Microsoft Defender for IoT Remote Code Execution Vulnerability | Important | 10 |
Microsoft Defender for IoT | - | - | - |
| CVE-2021-42312 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Defender for IoT | - | - | - |
| CVE-2021-42313 | Microsoft Defender for IoT Remote Code Execution Vulnerability | Important | 10 |
Microsoft Defender for IoT | - | - | - |
| CVE-2021-42314 | Microsoft Defender for IoT Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Defender for IoT | - | - | - |
| CVE-2021-42315 | Microsoft Defender for IoT Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Defender for IoT | - | - | - |
| CVE-2021-42294 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 7.2 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-43214 | Web Media Extensions Remote Code Execution Vulnerability | Important | 9.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-43215 | iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution | Critical | 9.8 |
Internet Storage Name Service | - | - | - |
| CVE-2021-43216 | Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Local Security Authority Server (lsasrv) | - | - | - |
| CVE-2021-43217 | Windows Encrypting File System (EFS) Remote Code Execution Vulnerability | Critical | 9.8 |
Windows Encrypting File System (EFS) | - | - | - |
| CVE-2021-43219 | DirectX Graphics Kernel File Denial of Service Vulnerability | Important | 7.5 |
Windows DirectX | - | - | - |
| CVE-2021-43222 | Microsoft Message Queuing Information Disclosure Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2021-43223 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Remote Access Connection Manager | - | - | - |
| CVE-2021-43224 | Windows Common Log File System Driver Information Disclosure Vulnerability | Important | 5.5 |
Windows Common Log File System Driver | - | - | Yes |
| CVE-2021-43225 | Bot Framework SDK Remote Code Execution Vulnerability | Important | 9.8 |
Azure Bot Framework SDK | - | - | - |
| CVE-2021-43226 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2021-43227 | Storage Spaces Controller Information Disclosure Vulnerability | Important | 5.5 |
Windows Storage Spaces Controller | - | - | - |
| CVE-2021-43228 | SymCrypt Denial of Service Vulnerability | Important | 7.5 |
Windows SymCrypt | - | - | - |
| CVE-2021-43229 | Windows NTFS Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NTFS | - | - | - |
| CVE-2021-43230 | Windows NTFS Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NTFS | - | - | - |
| CVE-2021-43231 | Windows NTFS Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NTFS | - | - | - |
| CVE-2021-43232 | Windows Event Tracing Remote Code Execution Vulnerability | Important | 7.8 |
Windows Event Tracing | - | - | - |
| CVE-2021-43233 | Remote Desktop Client Remote Code Execution Vulnerability | Critical | 7.5 |
Remote Desktop Client | - | - | - |
| CVE-2021-43234 | Windows Fax Service Remote Code Execution Vulnerability | Important | 7.8 |
Role: Windows Fax Service | - | - | - |
| CVE-2021-43235 | Storage Spaces Controller Information Disclosure Vulnerability | Important | 5.5 |
Windows Storage | - | - | - |
| CVE-2021-43236 | Microsoft Message Queuing Information Disclosure Vulnerability | Important | 7.5 |
Windows Message Queuing | - | - | - |
| CVE-2021-43237 | Windows Setup Elevation of Privilege Vulnerability | Important | 7.3 |
Windows Update Stack | - | - | - |
| CVE-2021-43238 | Windows Remote Access Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Remote Access Connection Manager | - | - | - |
| CVE-2021-43239 | Windows Recovery Environment Agent Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Update Stack | - | - | - |
| CVE-2021-43240 | NTFS Set Short Name Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NTFS | - | Yes | - |
| CVE-2021-43243 | VP9 Video Extensions Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-43244 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2021-43245 | Windows Digital TV Tuner Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Digital TV Tuner | - | - | - |
| CVE-2021-43246 | Windows Hyper-V Denial of Service Vulnerability | Important | 5.6 |
Role: Windows Hyper-V | - | - | - |
| CVE-2021-43247 | Windows TCP/IP Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows TCP/IP | - | - | - |
| CVE-2021-43248 | Windows Digital Media Receiver Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-43255 | Microsoft Office Trust Center Spoofing Vulnerability | Important | 5.5 |
Office Developer Platform | - | - | - |
| CVE-2021-43256 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2021-43875 | Microsoft Office Graphics Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2021-43877 | ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability | Important | 8.8 |
ASP.NET Core & Visual Studio | - | - | - |
| CVE-2021-43882 | Microsoft Defender for IoT Remote Code Execution Vulnerability | Important | 9.8 |
Microsoft Defender for IoT | - | - | - |
| CVE-2021-43883 | Windows Installer Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Installer | - | Yes | - |
| CVE-2021-43888 | Microsoft Defender for IoT Information Disclosure Vulnerability | Important | 7.5 |
Microsoft Defender for IoT | - | - | - |
| CVE-2021-43889 | Microsoft Defender for IoT Remote Code Execution Vulnerability | Important | 7.2 |
Microsoft Defender for IoT | - | - | - |
| CVE-2021-43891 | Visual Studio Code Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio Code | - | - | - |
| CVE-2021-43899 | Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability | Critical | 9.8 |
Microsoft Devices | - | - | - |
| CVE-2021-43907 | Visual Studio Code WSL Extension Remote Code Execution Vulnerability | Critical | 9.8 |
Visual Studio Code - WSL Extension | - | - | - |
| CVE-2021-43890 | Windows AppX Installer Spoofing Vulnerability | Important | 7.1 |
Apps | Yes | Yes | - |
| CVE-2021-43876 | Microsoft SharePoint Elevation of Privilege Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-40452 | HEVC Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-40453 | HEVC Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-41365 | Microsoft Defender for IoT Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Defender for IoT | - | - | - |
| CVE-2021-41333 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Print Spooler Components | - | Yes | - |
| CVE-2021-41360 | HEVC Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2021-42293 | Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability | Important | 6.5 |
Microsoft Office Access | - | - | - |
| CVE-2021-42309 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-42320 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.7 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-42295 | Visual Basic for Applications Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Office | - | - | - |
| CVE-2021-43207 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2021-43242 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.7 |
Microsoft Office SharePoint | - | - | - |
| CVE-2021-43880 | Windows Mobile Device Management Elevation of Privilege Vulnerability | Important | 5.5 |
Windows Mobile Device Management | - | Yes | - |
| CVE-2021-43893 | Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability | Important | 7.5 |
Windows Encrypting File System (EFS) | - | Yes | - |
| CVE-2021-43896 | Microsoft PowerShell Spoofing Vulnerability | Important | 5.5 |
Microsoft PowerShell | - | - | - |
| CVE-2021-43905 | Microsoft Office app Remote Code Execution Vulnerability | Critical | 9.6 |
Microsoft Office | - | - | - |
| CVE-2021-43908 | Visual Studio Code Spoofing Vulnerability | Important | 4.3 |
Visual Studio Code | - | - | - |
| CVE-2021-43892 | Microsoft BizTalk ESB Toolkit Spoofing Vulnerability | Important | 7.4 |
BizTalk ESB Toolkit | - | - | - |
Threat Categories 5
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 26 | 7 |
| Elevation of Privilege | 22 | - |
| Information Disclosure | 10 | - |
| Spoofing | 7 | - |
| Denial of Service | 3 | - |
Affected Products 38
| Product | CVEs | Exploited |
|---|---|---|
| Microsoft Defender for IoT | 10 | - |
| Microsoft Windows Codecs Library | 6 | - |
| Microsoft Office SharePoint | 5 | - |
| Windows NTFS | 4 | - |
| Microsoft Office | 3 | - |
| Windows Common Log File System Driver | 3 | - |
| Visual Studio Code | 2 | - |
| Windows Encrypting File System (EFS) | 2 | - |
| Windows Message Queuing | 2 | - |
| Windows Remote Access Connection Manager | 2 | - |
| Windows Update Stack | 2 | - |
| ASP.NET Core & Visual Studio | 1 | - |
| Apps | 1 | 1 |
| Azure Bot Framework SDK | 1 | - |
| BizTalk ESB Toolkit | 1 | - |
| Internet Storage Name Service | 1 | - |
| Microsoft Devices | 1 | - |
| Microsoft Local Security Authority Server (lsasrv) | 1 | - |
| Microsoft Office Access | 1 | - |
| Microsoft Office Excel | 1 | - |
| Microsoft PowerShell | 1 | - |
| Office Developer Platform | 1 | - |
| Remote Desktop Client | 1 | - |
| Role: Windows Fax Service | 1 | - |
| Role: Windows Hyper-V | 1 | - |
| Visual Studio Code - WSL Extension | 1 | - |
| Windows Digital TV Tuner | 1 | - |
| Windows DirectX | 1 | - |
| Windows Event Tracing | 1 | - |
| Windows Installer | 1 | - |
| Windows Kernel | 1 | - |
| Windows Media | 1 | - |
| Windows Mobile Device Management | 1 | - |
| Windows Print Spooler Components | 1 | - |
| Windows Storage | 1 | - |
| Windows Storage Spaces Controller | 1 | - |
| Windows SymCrypt | 1 | - |
| Windows TCP/IP | 1 | - |