CVE-2021-40472 – Microsoft Excel Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2021-40472
Microsoft Excel Information Disclosure Vulnerability Una vulnerabilidad de Divulgación de Información de Microsoft Excel • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40472 •
CVE-2021-40471 – Microsoft Excel Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-40471
Microsoft Excel Remote Code Execution Vulnerability Una vulnerabilidad de Ejecución de Código Remota de Microsoft Excel. Este ID de CVE es diferente de CVE-2021-40473, CVE-2021-40474, CVE-2021-40479, CVE-2021-40485 • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40471 •
CVE-2021-40454 – Rich Text Edit Control Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2021-40454
Rich Text Edit Control Information Disclosure Vulnerability Una vulnerabilidad de Divulgación de Información en Rich Text Edit Control • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40454 • CWE-312: Cleartext Storage of Sensitive Information •
CVE-2021-38658 – Microsoft Office Graphics Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-38658
Microsoft Office Graphics Remote Code Execution Vulnerability Una Vulnerabilidad de Ejecución de Código Remota en Microsoft Office Graphics. Este CVE ID es diferente de CVE-2021-38660 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DOC files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38658 https://www.zerodayinitiative.com/advisories/ZDI-21-1083 • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2021-38650 – Microsoft Office Spoofing Vulnerability
https://notcve.org/view.php?id=CVE-2021-38650
Microsoft Office Spoofing Vulnerability Una Vulnerabilidad de Suplantación de Identidad de Microsoft Office • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38650 •