CVE-2021-26869 – Windows ActiveX Installer Service Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2021-26869
Windows ActiveX Installer Service Information Disclosure Vulnerability Una Vulnerabilidad de Divulgación de Información del ActiveX Installer Service de Windows • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26869 •
CVE-2021-26868 – Windows Graphics Component Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2021-26868
Windows Graphics Component Elevation of Privilege Vulnerability Una Vulnerabilidad de Elevación de Privilegios del Graphics Component de Windows • https://github.com/KangD1W2/CVE-2021-26868 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26868 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2021-26867 – Windows Hyper-V Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-26867
Windows Hyper-V Remote Code Execution Vulnerability Una Vulnerabilidad de Ejecución de Código Remota de Windows Hyper-V • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26867 •
CVE-2021-26866 – Windows Update Service Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2021-26866
Windows Update Service Elevation of Privilege Vulnerability Una Vulnerabilidad de Elevación de Privilegios del Update Service de Windows This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within Windows Update Agent. By creating a directory junction, an attacker can abuse Windows Update Agent to delete a directory. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26866 https://www.zerodayinitiative.com/advisories/ZDI-21-286 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2021-26863 – Windows Win32k Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2021-26863
Windows Win32k Elevation of Privilege Vulnerability Una Vulnerabilidad de Elevación de Privilegios de Windows Win32k. Este ID de CVE es diferente de CVE-2021-26875, CVE-2021-26900, CVE-2021-27077 Microsoft Windows kernel suffers from a use-after-free of the PDEVOBJ object via a race condition vulnerability in NtGdiGetDeviceCapsAll. • http://packetstormsecurity.com/files/161768/Microsoft-Windows-Kernel-NtGdiGetDeviceCapsAll-Race-Condition-Use-After-Free.html https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26863 • CWE-269: Improper Privilege Management •