CVE-2021-42292 – Microsoft Excel Security Feature Bypass
https://notcve.org/view.php?id=CVE-2021-42292
Microsoft Excel Security Feature Bypass Vulnerability Una vulnerabilidad de Omisión de Funcionalidades de Seguridad de Microsoft Excel A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution. • https://github.com/corelight/CVE-2021-42292 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42292 •
CVE-2021-41368 – Microsoft Access Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-41368
Microsoft Access Remote Code Execution Vulnerability Una vulnerabilidad de Ejecución de Código Remota en Microsoft Access This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Access. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ACCDB database files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41368 https://www.zerodayinitiative.com/advisories/ZDI-21-1309 •
CVE-2021-40442 – Microsoft Excel Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-40442
Microsoft Excel Remote Code Execution Vulnerability Una vulnerabilidad de Ejecución de Código Remota de Microsoft Excel • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40442 •
CVE-2021-41354 – Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
https://notcve.org/view.php?id=CVE-2021-41354
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Una vulnerabilidad de tipo Cross-site Scripting de Microsoft Dynamics 365 (on-premises) • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41354 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-41353 – Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability
https://notcve.org/view.php?id=CVE-2021-41353
Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability Una vulnerabilidad de Suplantación de Identidad de Microsoft Dynamics 365 (on-premises) • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-41353 •