Info-security-vs-IT-security

November Security Vulnerabilities

We have compiled a list of Security Vulnerabilities that were discovered in November 2021. We are available to assist you if you need help applying or investigating these vulnerabilities. 

Contact for assistance solving Security Vulnerabilities

Google Chrome Vulnerabilities

CVE NumberDate of ReleaseSeverityDescription
CVE-2021-3800423/11/214.3Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2021-3800323/11/216.8Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-3800223/11/216.8Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVE-2021-3800123/11/216.8Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-3799923/11/214.3Insufficient data validation in New Tab Page in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to inject arbitrary scripts or HTML in a new browser tab via a crafted HTML page.
CVE-2021-3799823/11/216.8Use after free in Garbage Collection in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-3799723/11/216.8Use after free in Sign-In in Google Chrome prior to 95.0.4638.69 allowed a remote attacker who convinced a user to sign into Chrome to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-3799602/11/214.3Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a malicious file.
CVE-2021-3799502/11/214.3Inappropriate implementation in WebApp Installer in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially overlay and spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2021-3799402/11/214.3Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVE-2021-3799302/11/216.8Use after free in PDF Accessibility in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-3799202/11/216.8Out of bounds read in WebAudio in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-3799102/11/215.1Race in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-3799002/11/214.3Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to leak cross-origin data via a crafted app.
CVE-2021-3798902/11/214.3Inappropriate implementation in Blink in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to abuse content security policy via a crafted HTML page.
CVE-2021-3798802/11/216.8Use after free in Profiles in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who convinced a user to engage in specific gestures to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-3798702/11/216.8Use after free in Network APIs in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-3798602/11/216.8Heap buffer overflow in Settings in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to engage with Dev Tools to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-3798502/11/216.8Use after free in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had convinced a user to allow for connection to debugger to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-3798402/11/216.8Heap buffer overflow in PDFium in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-3798302/11/216.8Use after free in Dev Tools in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-3798202/11/216.8Use after free in Incognito in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-3798102/11/216.8Heap buffer overflow in Skia in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVE-2021-3797902/11/216.8heap buffer overflow in WebRTC in Google Chrome prior to 94.0.4606.81 allowed a remote attacker who convinced a user to browse to a malicious website to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-3797802/11/216.8Heap buffer overflow in Blink in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-3797702/11/216.8Use after free in Garbage Collection in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-649202/11/216.8Use after free in ANGLE in Google Chrome prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVE-2018-612502/11/214.3Insufficient policy enforcement in USB in Google Chrome on Windows prior to 67.0.3396.62 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page.
CVE-2018-612202/11/216.8Type confusion in WebAssembly in Google Chrome prior to 66.0.3359.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Firefox Vulnerabilities

CVE NumberDate of ReleaseSeverityDescription
CVE-2021-3850103/11/216.8Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
CVE-2021-3850003/11/216.8Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93.
CVE-2021-3849903/11/216.8Mozilla developers reported memory safety bugs present in Firefox 92. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93.
CVE-2021-3849803/11/215During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
CVE-2021-3849703/11/214.3Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
CVE-2021-3849603/11/216.8During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93.
CVE-2021-3849403/11/216.8Mozilla developers reported memory safety bugs present in Firefox 91. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 92.
CVE-2021-3849303/11/216.8Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.14, Thunderbird < 78.14, and Firefox < 92.
CVE-2021-3849103/11/214.3Mixed-content checks were unable to analyze opaque origins which led to some mixed content being loaded. This vulnerability affects Firefox < 92.
CVE-2021-2999303/11/215.8Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92.
CVE-2021-2999103/11/215.8Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attack against servers using HTTP/3. This vulnerability affects Firefox < 91.0.1 and Thunderbird < 91.0.1.

RedHat Enterprise Linux Vulnerabilities

CVE NumberDate of ReleaseSeverityDescription
CVE-2021-393522/11/215.1When PgBouncer is configured to use “cert” authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.
CVE-2021-367223/11/217.5A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

Windows 10 Vulnerabilities

CVE NumberDate of ReleaseSeverityDescription
CVE-2021-4228610/11/214.6Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability
CVE-2021-4228510/11/217.2Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-4228410/11/217.1Windows Hyper-V Denial of Service Vulnerability
CVE-2021-4228310/11/214.6NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41367, CVE-2021-41370.
CVE-2021-4228010/11/214.6Windows Feedback Hub Elevation of Privilege Vulnerability
CVE-2021-4227910/11/215.1Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2021-4227710/11/214.6Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
CVE-2021-4227610/11/216.8Microsoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2021-4227510/11/216.5Microsoft COM for Windows Remote Code Execution Vulnerability
CVE-2021-4137910/11/214.6Windows Installer Elevation of Privilege Vulnerability
CVE-2021-4137810/11/216.5Windows NTFS Remote Code Execution Vulnerability
CVE-2021-4137710/11/214.6Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
CVE-2021-4137010/11/214.6NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41367, CVE-2021-42283.
CVE-2021-4136710/11/214.6NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41370, CVE-2021-42283.
CVE-2021-4136610/11/214.6Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
CVE-2021-4135610/11/215Windows Denial of Service Vulnerability
CVE-2021-3866610/11/216.8Remote Desktop Client Remote Code Execution Vulnerability
CVE-2021-3866510/11/214.3Remote Desktop Protocol Client Information Disclosure Vulnerability
CVE-2021-3695710/11/214.6Windows Desktop Bridge Elevation of Privilege Vulnerability
CVE-2021-2644310/11/217.7Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability

Windows Server 2012 Vulnerabilities

CVE NumberDate of ReleaseSeverityDescription
CVE-2021-4229110/11/216.5Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42282, CVE-2021-42287.
CVE-2021-4228710/11/216.5Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42282, CVE-2021-42291.
CVE-2021-4228510/11/217.2Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-4228410/11/217.1Windows Hyper-V Denial of Service Vulnerability
CVE-2021-4228310/11/214.6NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41367, CVE-2021-41370.
CVE-2021-4228210/11/216.5Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42287, CVE-2021-42291.
CVE-2021-4227810/11/216.5Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42282, CVE-2021-42287, CVE-2021-42291.
CVE-2021-4227510/11/216.5Microsoft COM for Windows Remote Code Execution Vulnerability
CVE-2021-4137910/11/214.6Windows Installer Elevation of Privilege Vulnerability
CVE-2021-4137710/11/214.6Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
CVE-2021-4137010/11/214.6NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41367, CVE-2021-42283.
CVE-2021-4136710/11/214.6NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41370, CVE-2021-42283.
CVE-2021-4136610/11/214.6Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
CVE-2021-3866610/11/216.8Remote Desktop Client Remote Code Execution Vulnerability
CVE-2021-3866510/11/214.3Remote Desktop Protocol Client Information Disclosure Vulnerability

Windows Server 2016 Vulnerabilities

CVE NumberDate of ReleaseSeverityDescription
CVE-2021-4229110/11/216.5Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42282, CVE-2021-42287.
CVE-2021-4228710/11/216.5Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42282, CVE-2021-42291.
CVE-2021-4228510/11/217.2Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-4228410/11/217.1Windows Hyper-V Denial of Service Vulnerability
CVE-2021-4228310/11/214.6NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41367, CVE-2021-41370.
CVE-2021-4228210/11/216.5Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42287, CVE-2021-42291.
CVE-2021-4228010/11/214.6Windows Feedback Hub Elevation of Privilege Vulnerability
CVE-2021-4227910/11/215.1Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2021-4227810/11/216.5Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42282, CVE-2021-42287, CVE-2021-42291.
CVE-2021-4227710/11/214.6Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
CVE-2021-4227610/11/216.8Microsoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2021-4227510/11/216.5Microsoft COM for Windows Remote Code Execution Vulnerability
CVE-2021-4137910/11/214.6Windows Installer Elevation of Privilege Vulnerability
CVE-2021-4137810/11/216.5Windows NTFS Remote Code Execution Vulnerability
CVE-2021-4137710/11/214.6Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
CVE-2021-4137010/11/214.6NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41367, CVE-2021-42283.
CVE-2021-4136710/11/214.6NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41370, CVE-2021-42283.
CVE-2021-4136610/11/214.6Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
CVE-2021-4135610/11/215Windows Denial of Service Vulnerability
CVE-2021-3866610/11/216.8Remote Desktop Client Remote Code Execution Vulnerability
CVE-2021-3866510/11/214.3Remote Desktop Protocol Client Information Disclosure Vulnerability
CVE-2021-3695710/11/214.6Windows Desktop Bridge Elevation of Privilege Vulnerability
CVE-2021-2644310/11/217.7Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability

Windows Server 2019 Vulnerabilities

CVE NumberDate of ReleaseSeverityDescription
CVE-2021-4229110/11/216.5Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42282, CVE-2021-42287.
CVE-2021-4228710/11/216.5Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42282, CVE-2021-42291.
CVE-2021-4228510/11/217.2Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-4228410/11/217.1Windows Hyper-V Denial of Service Vulnerability
CVE-2021-4228310/11/214.6NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41367, CVE-2021-41370.
CVE-2021-4228210/11/216.5Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42278, CVE-2021-42287, CVE-2021-42291.
CVE-2021-4228010/11/214.6Windows Feedback Hub Elevation of Privilege Vulnerability
CVE-2021-4227910/11/215.1Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2021-4227810/11/216.5Active Directory Domain Services Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-42282, CVE-2021-42287, CVE-2021-42291.
CVE-2021-4227710/11/214.6Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
CVE-2021-4227610/11/216.8Microsoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2021-4227510/11/216.5Microsoft COM for Windows Remote Code Execution Vulnerability
CVE-2021-4137910/11/214.6Windows Installer Elevation of Privilege Vulnerability
CVE-2021-4137810/11/216.5Windows NTFS Remote Code Execution Vulnerability
CVE-2021-4137710/11/214.6Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
CVE-2021-4137010/11/214.6NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41367, CVE-2021-42283.
CVE-2021-4136710/11/214.6NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-41370, CVE-2021-42283.
CVE-2021-4136610/11/214.6Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
CVE-2021-4135610/11/215Windows Denial of Service Vulnerability
CVE-2021-3866610/11/216.8Remote Desktop Client Remote Code Execution Vulnerability
CVE-2021-3866510/11/214.3Remote Desktop Protocol Client Information Disclosure Vulnerability
CVE-2021-3695710/11/214.6Windows Desktop Bridge Elevation of Privilege Vulnerability
CVE-2021-2644310/11/217.7Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability

VMware vCenter Vulnerabilities

CVE NumberDate of ReleaseSeverityDescription
CVE-2021-2204924/11/217.5The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.
CVE-2021-2204810/11/216.5The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a higher privileged group.
CVE-2021-2198024/11/215The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.

For more information and pricing for any of our services either for yourself or for your customers you can contact us below