PatchSiren

Microsoft CVE debriefs · Page 72

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-38645

CVE-2021-38645 is a Microsoft Open Management Infrastructure (OMI) privilege escalation vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 with a remediation due date of 2021-11-17, which makes patching urgent for any affected environment. The supplied sources do not include exploit mechanics, affected versions, or other technical scope details, so the safest respons [truncated]

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-36955

CVE-2021-36955 affects the Microsoft Windows Common Log File System (CLFS) driver and is described as a privilege escalation vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 and marked known ransomware campaign use, indicating it should be treated as a high-priority remediation item. CISA’s required action is to apply updates per vendor instructions.

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-36948

CVE-2021-36948 is a Microsoft Windows privilege escalation vulnerability associated with Windows Update Medic Service. CISA included it in the Known Exploited Vulnerabilities catalog on 2021-11-03, which means defenders should treat it as an actively tracked exploitation risk and prioritize vendor updates. CISA set a remediation due date of 2021-11-17, leaving a short window for patching and verification.

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-36942

CVE-2021-36942 is a Microsoft Windows Local Security Authority (LSA) spoofing vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. CISA also marks it as associated with known ransomware campaign use, so this should be treated as a high-priority patching item for Windows environments.

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-34527

CVE-2021-34527 is a Microsoft Windows Print Spooler remote code execution issue that CISA lists in its Known Exploited Vulnerabilities catalog. The KEV entry marks it as known to be used in ransomware campaigns and directs defenders to apply vendor updates, with CISA ED 21-04 providing additional guidance and requirements.

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-34523

CVE-2021-34523 is a Microsoft Exchange Server privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because it is tracked as known exploited and marked for known ransomware campaign use, organizations running Exchange Server should treat remediation as urgent and follow vendor update guidance without delay. CISA’s KEV entry specifies that the requ [truncated]

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-34473

CVE-2021-34473 is a Microsoft Exchange Server remote code execution vulnerability that CISA listed in its Known Exploited Vulnerabilities catalog. The entry indicates known exploitation and known ransomware campaign use, so organizations running Exchange Server should treat remediation as urgent and apply Microsoft updates per vendor instructions.

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-34448

CVE-2021-34448 is a Microsoft Windows Scripting Engine memory corruption vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because CISA identified it as known to be exploited and set a remediation due date of 2021-11-17, this should be treated as a high-priority patching issue for Windows environments. The supplied sources do not include a vendor bulletin or patch KB, so remedi [truncated]

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-33771

CVE-2021-33771 is a Microsoft Windows kernel privilege escalation vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2021-11-03. That listing means CISA had enough evidence to classify it as actively exploited in the wild. No CVSS score was provided in the supplied source corpus, and the known ransomware campaign use field is listed as unknown. Organizations running affected W [truncated]

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-33742

CVE-2021-33742 is a Microsoft Windows MSHTML Platform remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog. Because it is listed as known exploited, organizations should treat remediation as urgent and follow vendor update guidance without delay.

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-33739

CVE-2021-33739 is a Microsoft Windows privilege escalation issue affecting the Desktop Window Manager (DWM) core library. Because CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, defenders should treat it as actively exploited and prioritize Microsoft’s remediation guidance.

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-31979

CVE-2021-31979 is a Microsoft Windows kernel privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03, with remediation due by 2021-11-17. Because CISA flagged it as known exploited, Windows systems should be prioritized for patching and validation even though the available source record provides limited technical detail.

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-31956

CVE-2021-31956 is a Microsoft Windows NTFS privilege escalation vulnerability that CISA included in its Known Exploited Vulnerabilities catalog on 2021-11-03. Because CISA lists it as known exploited, defenders should treat it as a high-priority patching and exposure-reduction item and follow vendor update guidance without delay.

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-31955

CVE-2021-31955 is a Microsoft Windows Kernel information disclosure vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2021-11-03. Because CISA marked it as known exploited and set a remediation due date of 2021-11-17, defenders should treat it as a high-priority patching item for Windows environments.

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-31207

CVE-2021-31207 is a Microsoft Exchange Server security feature bypass vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. The KEV entry indicates known exploitation and sets a remediation due date of 2021-11-17, with CISA’s required action to apply updates per vendor instructions. The supplied corpus also marks this vulnerability as associated with known ransomware [truncated]

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-31201

CVE-2021-31201 is a Microsoft Enhanced Cryptographic Provider privilege-escalation vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2021-11-03. Because it is a KEV-listed issue, defenders should treat it as actively exploited or otherwise high-risk and prioritize remediation using Microsoft’s update guidance.

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-31199

CVE-2021-31199 is a Microsoft Enhanced Cryptographic Provider privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because it is in the KEV catalog, defenders should treat it as actively exploited or of confirmed exploitation concern and prioritize remediation using vendor guidance. The source corpus does not include deeper technical exploitation [truncated]

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-28310

CVE-2021-28310 is a Microsoft Win32k privilege escalation vulnerability that CISA included in its Known Exploited Vulnerabilities catalog on 2021-11-03. Because it is listed as known exploited, defenders should treat it as a high-priority remediation item and apply vendor updates without delay. The supplied metadata sets a remediation due date of 2021-11-17, and the known ransomware campaign use field is [truncated]

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-27085

CVE-2021-27085 is a Microsoft Internet Explorer remote code execution vulnerability. In the supplied source corpus, CISA listed it in the Known Exploited Vulnerabilities catalog on 2021-11-03, indicating known exploitation and making remediation time-sensitive. CISA’s due date for applying updates was 2021-11-17.

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-27065

CVE-2021-27065 is a Microsoft Exchange Server remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because it is a KEV-listed issue and CISA notes known ransomware campaign use, organizations running Exchange Server should treat it as a high-priority remediation item and apply vendor updates without delay.

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-27059

CVE-2021-27059 is a Microsoft Office remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. The CISA entry indicates this issue was actively exploited and required prompt remediation. The supplied source corpus does not include technical exploit details or affected-version specifics, so the safest response is to treat all relevant Microsoft Office [truncated]

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-26858

CVE-2021-26858 is a Microsoft Exchange Server remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. CISA records known ransomware campaign use, which makes this a high-priority patching issue for organizations that still operate affected Exchange deployments.

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-26857

CVE-2021-26857 is a Microsoft Exchange Server remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog. Because it is listed as known exploited and marked for known ransomware campaign use, organizations running Exchange Server should treat remediation as urgent and follow Microsoft’s update guidance plus CISA’s ED 21-02 requirements.

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-26855

CVE-2021-26855 is a Microsoft Exchange Server remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because it is on KEV and marked as having known ransomware campaign use, it should be treated as an urgent remediation item. CISA’s guidance for this entry is to apply updates per vendor instructions, with additional direction referenced in Emergen [truncated]

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-26411

CVE-2021-26411 is a Microsoft Internet Explorer memory corruption vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. The KEV listing indicates it was already being exploited in the wild, and CISA marked the required action as applying updates per vendor instructions. No CVSS score was provided in the supplied record, so remediation priority should be driven by the [truncated]

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-1732

CVE-2021-1732 is a Microsoft Win32k privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. CISA also marked it as associated with known ransomware campaign use and set a remediation due date of 2021-11-17. Based on the available source data, the safest defensive response is to apply Microsoft updates per vendor instructions and prioritize this issu [truncated]

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-1675

CVE-2021-1675 is a Microsoft Windows Print Spooler remote code execution vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. Because it is a KEV item and marked with known ransomware campaign use, organizations should treat remediation as time-sensitive and follow Microsoft’s update guidance without delay.

Known exploited Microsoft CVE published 2021-11-03

CVE-2021-1647

CVE-2021-1647 is a Microsoft Defender remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because it is on the KEV list, defenders should treat it as actively exploited risk and prioritize vendor-supplied updates and mitigation steps over routine patch scheduling.

Known exploited Microsoft CVE published 2021-11-03

CVE-2020-17144

CVE-2020-17144 is a Microsoft Exchange Server remote code execution vulnerability that CISA included in its Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is that this issue should be treated as high priority and remediated according to vendor guidance. The KEV listing indicates it is considered actively relevant to real-world exploitation risk, so patch status and exposure shoul [truncated]

Known exploited Microsoft CVE published 2021-11-03

CVE-2020-17087

CVE-2020-17087 is a Microsoft Windows kernel privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because it appears in KEV, defenders should treat it as an active risk and prioritize vendor-recommended updates rather than waiting for routine maintenance windows.