SECURITY ALERTS

Multiple Vulnerabilities Exist in Windows

DESCRIPTION:

Multiple vulnerabilities exist in Windows that could allow for arbitrary code execution or privilege escalation.

1. Remote code execution vulnerability:

   CVE-2021-36965 and CVE-2021-38647

2. Privilege escalation vulnerability:

    CVE-2021-36955、CVE-2021-36963、CVE-2021-36968、CVE-2021-38633、CVE-2021-38645、CVE-2021-38648、CVE-2021-38649、CVE-2021-38667、CVE-2021-3867 and CVE-2021-40447

 

AFFECTED RELEASES:

-CVE-2021-36955、CVE-2021-36963、CVE-2021-36965、CVE-2021-38633、CVE-2021-38667、CVE-2021-3867 and CVE-2021-40447:

Windows 7 for 32-bit Systems Service Pack 1

Windows 7 for x64-based Systems Service Pack 1

Windows 8.1 for 32-bit systems

Windows 8.1 for x64-based systems

Windows RT 8.1

Windows 10 for 32-bit Systems

Windows 10 for x64-based Systems

Windows 10 Version 1607 for 32-bit Systems

Windows 10 Version 1607 for x64-based Systems

Windows 10 Version 1809 for 32-bit Systems

Windows 10 Version 1809 for ARM64-based Systems

Windows 10 Version 1809 for x64-based Systems

Windows 10 Version 1909 for 32-bit Systems

Windows 10 Version 1909 for ARM64-based Systems

Windows 10 Version 1909 for x64-based Systems

Windows 10 Version 2004 for 32-bit Systems

Windows 10 Version 2004 for ARM64-based Systems

Windows 10 Version 2004 for x64-based Systems

Windows 10 Version 20H2 for 32-bit Systems

Windows 10 Version 20H2 for ARM64-based Systems

Windows 10 Version 20H2 for x64-based Systems

Windows 10 Version 21H1 for 32-bit Systems

Windows 10 Version 21H1 for ARM64-based Systems

Windows 10 Version 21H1 for x64-based Systems

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for x64-based Systems Service Pack 2

Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Windows Server 2012

Windows Server 2012 (Server Core installation)

Windows Server 2012 R2

Windows Server 2012 R2 (Server Core installation)

Windows Server 2016

Windows Server 2016  (Server Core installation)

Windows Server 2019

Windows Server 2019  (Server Core installation)

Windows Server 2022

Windows Server 2022 (Server Core installation)

Windows Server, version 2004 (Server Core installation)

Windows Server, version 20H2 (Server Core Installation)

 

- CVE-2021-38645、CVE-2021-38647、CVE-2021-38648 and CVE-2021-38649:

Azure Open Management Infrastructure

 

- CVE-2021-36968:

Windows 7 for 32-bit Systems Service Pack 1

Windows 7 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for x64-based Systems Service Pack 2

Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

 

SOLUTION:

Users and system administrators of affected products are advised to apply the security updates immediately from the following URL:

1.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36955

2.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36963

3.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36965

4.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36968

5.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38633

6.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38645

7.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38647

8.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38648 9.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38649

10.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38667

11.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38671

12.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40447

 

REFERENCE:

1.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36955
2.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36963
3.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36965
4.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36968
5.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38633
6.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38645
7.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38647
8.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38648 9.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38649
10.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38667
11.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38671
12.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40447

Back To Top