NovaVibe

98 CVEs were discovered during the May security report

  • CVEs stand for Common Vulnerabilities and Exposures, and they vary in form and what they affect.
  • During Patch Tuesday, a report of all CVEs is released to the general public.
  • CVEs are rated based on severity, from Important, to the more serious ones rated as Critical.
  • Read more about this month's CVE,s and update your PC if needed.

We all know that the focus of the Patch Tuesday updates is the improvement of the Windows experience for users, but they aren’t only about adding, enhancing, and fixing features.

However, another key aspect to these updates is the security improvements that come with them, and that’s pretty much why we recommend that everyone get these updates as soon as they become available in your region.

Well, May 11th is here, and so are the Patch Tuesday updates, and this means that the CVE reports are here as well.

So far, 2021 has been quite abundant in CVEs, with the following numbers being discovered each month:

All in all, here’s a brief rundown of this month’s CVE situation for both Adobe and Microsoft-related products, and we will also highlight some of the more severe ones detected.

The May CVE report includes 98 identified CVEs

Vulnerabilities found in Adobe products

Adobe has released a total of 12 patches that are meant to fix 43 identified CVEs that affected Experience Manager, InDesign, Illustrator, InCopy, Adobe Genuine Service, Acrobat and Reader, Magento, Creative Cloud Desktop, Media Encoder, Medium, and Animate.

Of the 43 total Adobe CVEs, 14 targeted Adobe Acrobat Reader, one of which has still been left unresolved, and they can be used to exploit user data via modified PDFs opened in Acrobat.

Vulnerabilities found in Microsoft products

The bulk of this month’s CVE report, as always, is the Microsoft-related CVEs, and they add up to a grand total of 55.

These CVEs target Microsoft Windows, .NET Core and Visual Studio, Internet Explorer (IE), Microsoft Office, SharePoint Server, Open-Source Software, Hyper-V, Skype for Business and Microsoft Lync, and Exchange Server.

As far as severity is concerned of these 55 bugs, they were rated as follows:

  • 4 are rated as Critical
  • 50 are rated Important
  • One is rated Moderate in severity.

Which were some of the most severe CVEs?

Some CVEs stand out in this report either because of how easily they were to exploit, or the popularity of teh program that was targeted, and they are the following:

Here’s a complete list of all the CVEs included in this month’s report:

CVE

Title

Severity

CVE-2021-31204.NET Core and Visual Studio Elevation of Privilege VulnerabilityImportant
CVE-2021-31200Common Utilities Remote Code Execution VulnerabilityImportant
CVE-2021-31207Microsoft Exchange Server Security Feature Bypass VulnerabilityModerate
CVE-2021-31166HTTP Protocol Stack Remote Code Execution VulnerabilityCritical
CVE-2021-28476Hyper-V Remote Code Execution VulnerabilityCritical
CVE-2021-31194OLE Automation Remote Code Execution VulnerabilityCritical
CVE-2021-26419Scripting Engine Memory Corruption VulnerabilityCritical
CVE-2021-28461Dynamics Finance and Operations Cross-site Scripting VulnerabilityImportant
CVE-2021-31936Microsoft Accessibility Insights for Web Information Disclosure VulnerabilityImportant
CVE-2021-31182Microsoft Bluetooth Driver Spoofing VulnerabilityImportant
CVE-2021-31174Microsoft Excel Information Disclosure VulnerabilityImportant
CVE-2021-31195Microsoft Exchange Server Remote Code Execution VulnerabilityImportant
CVE-2021-31198Microsoft Exchange Server Remote Code Execution VulnerabilityImportant
CVE-2021-31209Microsoft Exchange Server Spoofing VulnerabilityImportant
CVE-2021-28455Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution VulnerabilityImportant
CVE-2021-31180Microsoft Office Graphics Remote Code Execution VulnerabilityImportant
CVE-2021-31178Microsoft Office Information Disclosure VulnerabilityImportant
CVE-2021-31175Microsoft Office Remote Code Execution VulnerabilityImportant
CVE-2021-31176Microsoft Office Remote Code Execution VulnerabilityImportant
CVE-2021-31177Microsoft Office Remote Code Execution VulnerabilityImportant
CVE-2021-31179Microsoft Office Remote Code Execution VulnerabilityImportant
CVE-2021-31171Microsoft SharePoint Information Disclosure VulnerabilityImportant
CVE-2021-31181Microsoft SharePoint Remote Code Execution VulnerabilityImportant
CVE-2021-31173Microsoft SharePoint Server Information Disclosure VulnerabilityImportant
CVE-2021-28474Microsoft SharePoint Server Remote Code Execution VulnerabilityImportant
CVE-2021-26418Microsoft SharePoint Spoofing VulnerabilityImportant
CVE-2021-28478Microsoft SharePoint Spoofing VulnerabilityImportant
CVE-2021-31172Microsoft SharePoint Spoofing VulnerabilityImportant
CVE-2021-31184Microsoft Windows Infrared Data Association (IrDA) Information Disclosure VulnerabilityImportant
CVE-2021-26422Skype for Business and Lync Remote Code Execution VulnerabilityImportant
CVE-2021-26421Skype for Business and Lync Spoofing VulnerabilityImportant
CVE-2021-31214Visual Studio Code Remote Code Execution VulnerabilityImportant
CVE-2021-31211Visual Studio Code Remote Development Extension Remote Code Execution VulnerabilityImportant
CVE-2021-31213Visual Studio Code Remote Development Extension Remote Code Execution VulnerabilityImportant
CVE-2021-27068Visual Studio Remote Code Execution VulnerabilityImportant
CVE-2021-28465Web Media Extensions Remote Code Execution VulnerabilityImportant
CVE-2021-31190Windows Container Isolation FS Filter Driver Elevation of Privilege VulnerabilityImportant
CVE-2021-31165Windows Container Manager Service Elevation of Privilege VulnerabilityImportant
CVE-2021-31167Windows Container Manager Service Elevation of Privilege VulnerabilityImportant
CVE-2021-31168Windows Container Manager Service Elevation of Privilege VulnerabilityImportant
CVE-2021-31169Windows Container Manager Service Elevation of Privilege VulnerabilityImportant
CVE-2021-31208Windows Container Manager Service Elevation of Privilege VulnerabilityImportant
CVE-2021-28479Windows CSC Service Information Disclosure VulnerabilityImportant
CVE-2021-31185Windows Desktop Bridge Denial of Service VulnerabilityImportant
CVE-2021-31170Windows Graphics Component Elevation of Privilege VulnerabilityImportant
CVE-2021-31188Windows Graphics Component Elevation of Privilege VulnerabilityImportant
CVE-2021-31192Windows Media Foundation Core Remote Code Execution VulnerabilityImportant
CVE-2021-31191Windows Projected File System FS Filter Driver Information Disclosure VulnerabilityImportant
CVE-2021-31186Windows Remote Desktop Protocol (RDP) Information Disclosure VulnerabilityImportant
CVE-2021-31205Windows SMB Client Security Feature Bypass VulnerabilityImportant
CVE-2021-31193Windows SSDP Service Elevation of Privilege VulnerabilityImportant
CVE-2021-31187Windows WalletService Elevation of Privilege VulnerabilityImportant
CVE-2020-24587Windows Wireless Networking Information Disclosure VulnerabilityImportant
CVE-2020-24588Windows Wireless Networking Spoofing VulnerabilityImportant
CVE-2020-26144Windows Wireless Networking Spoofing VulnerabilityImportant

That being said, we will conclude our overview of this month’s CVE report, and we recommend that anyone using any of the affected Adobe or Microsoft products apply the latest Patch Tuesday updates as soon as possible.

On the other hand, users could always try third-party antiviruses to help with security, since they work just as well, if not better, than updating your PC.

Let us know what you think about this month’s CVE report by leaving us your feedback in the comments section below.

ncG1vNJzZmivmaOxsMPSq5ypp6Kpe6S7zGinmqyTnXq1wcSsm5qxXZjDpnnMmrBmamBnfnA%3D

Fernande Dalal

Update: 2024-06-17