Microsoft April 2021 Patch Tuesday fixes 108 flaws, 5 zero-days – BleepingComputer

TagCVE IDCVE TitleSeverityAzure AD Web Sign-inCVE-2021-27092Azure AD Web Sign-in Security Feature Bypass VulnerabilityImportantAzure DevOpsCVE-2021-28459Azure DevOps Server Spoofing VulnerabilityImportantAzure DevOpsCVE-2021-27067Azure DevOps Server and Team Foundation Server Information Disclosure VulnerabilityImportantAzure SphereCVE-2021-28460Azure Sphere Unsigned Code Execution VulnerabilityCriticalMicrosoft Edge (Chromium-based)CVE-2021-21199Chromium: CVE-2021-21199 Use Use after free in AuraUnknownMicrosoft Edge (Chromium-based)CVE-2021-21194Chromium: CVE-2021-21194 Use after free in screen captureUnknownMicrosoft Edge (Chromium-based)CVE-2021-21197Chromium: CVE-2021-21197 Heap buffer overflow in TabStripUnknownMicrosoft Edge (Chromium-based)CVE-2021-21198Chromium: CVE-2021-21198 Out of bounds read in IPCUnknownMicrosoft Edge (Chromium-based)CVE-2021-21195Chromium: CVE-2021-21195 Use after free in V8UnknownMicrosoft Edge (Chromium-based)CVE-2021-21196Chromium: CVE-2021-21196 Heap buffer overflow in TabStripUnknownMicrosoft Exchange ServerCVE-2021-28480Microsoft Exchange Server Remote Code Execution VulnerabilityCriticalMicrosoft Exchange ServerCVE-2021-28482Microsoft Exchange Server Remote Code Execution VulnerabilityCriticalMicrosoft Exchange ServerCVE-2021-28483Microsoft Exchange Server Remote Code Execution VulnerabilityCriticalMicrosoft Exchange ServerCVE-2021-28481Microsoft Exchange Server Remote Code Execution VulnerabilityCriticalMicrosoft Graphics ComponentCVE-2021-28350Windows GDI+ Remote Code Execution VulnerabilityImportantMicrosoft Graphics ComponentCVE-2021-28318Windows GDI+ Information Disclosure VulnerabilityImportantMicrosoft Graphics ComponentCVE-2021-28348Windows GDI+ Remote Code Execution VulnerabilityImportantMicrosoft Graphics ComponentCVE-2021-28349Windows GDI+ Remote Code Execution VulnerabilityImportantMicrosoft Internet Messaging APICVE-2021-27089Microsoft Internet Messaging API Remote Code Execution VulnerabilityImportantMicrosoft NTFSCVE-2021-28312Windows NTFS Denial of Service VulnerabilityModerateMicrosoft NTFSCVE-2021-27096NTFS Elevation of Privilege VulnerabilityImportantMicrosoft Office ExcelCVE-2021-28456Microsoft Excel Information Disclosure VulnerabilityImportantMicrosoft Office ExcelCVE-2021-28451Microsoft Excel Remote Code Execution VulnerabilityImportantMicrosoft Office ExcelCVE-2021-28454Microsoft Excel Remote Code Execution VulnerabilityImportantMicrosoft Office ExcelCVE-2021-28449Microsoft Office Remote Code Execution VulnerabilityImportantMicrosoft Office OutlookCVE-2021-28452Microsoft Outlook Memory Corruption VulnerabilityImportantMicrosoft Office SharePointCVE-2021-28450Microsoft SharePoint Denial of Service UpdateImportantMicrosoft Office WordCVE-2021-28453Microsoft Word Remote Code Execution VulnerabilityImportantMicrosoft Windows Codecs LibraryCVE-2021-28464VP9 Video Extensions Remote Code Execution VulnerabilityImportantMicrosoft Windows Codecs LibraryCVE-2021-28466Raw Image Extension Remote Code Execution VulnerabilityImportantMicrosoft Windows Codecs LibraryCVE-2021-27079Windows Media Photo Codec Information Disclosure VulnerabilityImportantMicrosoft Windows Codecs LibraryCVE-2021-28468Raw Image Extension Remote Code Execution VulnerabilityImportantMicrosoft Windows Codecs LibraryCVE-2021-28317Microsoft Windows Codecs Library Information Disclosure VulnerabilityImportantMicrosoft Windows DNSCVE-2021-28323Windows DNS Information Disclosure VulnerabilityImportantMicrosoft Windows DNSCVE-2021-28328Windows DNS Information Disclosure VulnerabilityImportantMicrosoft Windows SpeechCVE-2021-28351Windows Speech Runtime Elevation of Privilege VulnerabilityImportantMicrosoft Windows SpeechCVE-2021-28436Windows Speech Runtime Elevation of Privilege VulnerabilityImportantMicrosoft Windows SpeechCVE-2021-28347Windows Speech Runtime Elevation of Privilege VulnerabilityImportantOpen Source SoftwareCVE-2021-28458Azure ms-rest-nodeauth Library Elevation of Privilege VulnerabilityImportantRole: Hyper-VCVE-2021-28441Windows Hyper-V Information Disclosure VulnerabilityImportantRole: Hyper-VCVE-2021-28314Windows Hyper-V Elevation of Privilege VulnerabilityImportantRole: Hyper-VCVE-2021-28444Windows Hyper-V Security Feature Bypass VulnerabilityImportantRole: Hyper-VCVE-2021-26416Windows Hyper-V Denial of Service VulnerabilityImportantVisual StudioCVE-2021-27064Visual Studio Installer Elevation of Privilege VulnerabilityImportantVisual Studio CodeCVE-2021-28457Visual Studio Code Remote Code Execution VulnerabilityImportantVisual Studio CodeCVE-2021-28471Remote Development Extension for Visual Studio Code Remote Code Execution VulnerabilityImportantVisual Studio CodeCVE-2021-28475Visual Studio Code Remote Code Execution VulnerabilityImportantVisual Studio CodeCVE-2021-28473Visual Studio Code Remote Code Execution VulnerabilityImportantVisual Studio CodeCVE-2021-28477Visual Studio Code Remote Code Execution VulnerabilityImportantVisual Studio CodeCVE-2021-28469Visual Studio Code Remote Code Execution VulnerabilityImportantVisual Studio Code – GitHub Pull Requests and Issues ExtensionCVE-2021-28470Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution VulnerabilityImportantVisual Studio Code – Kubernetes ToolsCVE-2021-28448Visual Studio Code Kubernetes Tools Remote Code Execution VulnerabilityImportantVisual Studio Code – Maven for Java ExtensionCVE-2021-28472Visual Studio Code Maven for Java Extension Remote Code Execution VulnerabilityImportantWindows Application Compatibility CacheCVE-2021-28311Windows Application Compatibility Cache Denial of Service VulnerabilityImportantWindows AppX Deployment ExtensionsCVE-2021-28326Windows AppX Deployment Server Denial of Service VulnerabilityImportantWindows Console DriverCVE-2021-28438Windows Console Driver Denial of Service VulnerabilityImportantWindows Console DriverCVE-2021-28443Windows Console Driver Denial of Service VulnerabilityImportantWindows Diagnostic HubCVE-2021-28313Diagnostics Hub Standard Collector Service Elevation of Privilege VulnerabilityImportantWindows Diagnostic HubCVE-2021-28321Diagnostics Hub Standard Collector Service Elevation of Privilege VulnerabilityImportantWindows Diagnostic HubCVE-2021-28322Diagnostics Hub Standard Collector Service Elevation of Privilege VulnerabilityImportantWindows Early Launch Antimalware DriverCVE-2021-28447Windows Early Launch Antimalware Driver Security Feature Bypass VulnerabilityImportantWindows ELAMCVE-2021-27094Windows Early Launch Antimalware Driver Security Feature Bypass VulnerabilityImportantWindows Event TracingCVE-2021-27088Windows Event Tracing Elevation of Privilege VulnerabilityImportantWindows Event TracingCVE-2021-28435Windows Event Tracing Information Disclosure VulnerabilityImportantWindows InstallerCVE-2021-26413Windows Installer Spoofing VulnerabilityImportantWindows InstallerCVE-2021-28440Windows Installer Elevation of Privilege VulnerabilityImportantWindows InstallerCVE-2021-28437Windows Installer Information Disclosure VulnerabilityImportantWindows InstallerCVE-2021-26415Windows Installer Elevation of Privilege VulnerabilityImportantWindows KernelCVE-2021-27093Windows Kernel Information Disclosure VulnerabilityImportantWindows KernelCVE-2021-28309Windows Kernel Information Disclosure VulnerabilityImportantWindows Media PlayerCVE-2021-28315Windows Media Video Decoder Remote Code Execution VulnerabilityCriticalWindows Media PlayerCVE-2021-27095Windows Media Video Decoder Remote Code Execution VulnerabilityCriticalWindows Network File SystemCVE-2021-28445Windows Network File System Remote Code Execution VulnerabilityImportantWindows Overlay FilterCVE-2021-26417Windows Overlay Filter Information Disclosure VulnerabilityImportantWindows PortmappingCVE-2021-28446Windows Portmapping Information Disclosure VulnerabilityImportantWindows RegistryCVE-2021-27091RPC Endpoint Mapper Service Elevation of Privilege VulnerabilityImportantWindows Remote Procedure Call RuntimeCVE-2021-28336Remote Procedure Call Runtime Remote Code Execution VulnerabilityCriticalWindows Remote Procedure Call RuntimeCVE-2021-28335Remote Procedure Call Runtime Remote Code Execution VulnerabilityCriticalWindows Remote Procedure Call RuntimeCVE-2021-28334Remote Procedure Call Runtime Remote Code Execution VulnerabilityCriticalWindows Remote Procedure Call RuntimeCVE-2021-28338Remote Procedure Call Runtime Remote Code Execution VulnerabilityCriticalWindows Remote Procedure Call RuntimeCVE-2021-28434Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportantWindows Remote Procedure Call RuntimeCVE-2021-28337Remote Procedure Call Runtime Remote Code Execution VulnerabilityCriticalWindows Remote Procedure Call RuntimeCVE-2021-28333Remote Procedure Call Runtime Remote Code Execution VulnerabilityCriticalWindows Remote Procedure Call RuntimeCVE-2021-28327Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportantWindows Remote Procedure Call RuntimeCVE-2021-28329Remote Procedure Call Runtime Remote Code Execution VulnerabilityCriticalWindows Remote Procedure Call RuntimeCVE-2021-28330Remote Procedure Call Runtime Remote Code Execution VulnerabilityCriticalWindows Remote Procedure Call RuntimeCVE-2021-28332Remote Procedure Call Runtime Remote Code Execution VulnerabilityCriticalWindows Remote Procedure Call RuntimeCVE-2021-28331Remote Procedure Call Runtime Remote Code Execution VulnerabilityCriticalWindows Remote Procedure Call RuntimeCVE-2021-28354Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportantWindows Remote Procedure Call RuntimeCVE-2021-28339Remote Procedure Call Runtime Remote Code Execution VulnerabilityCriticalWindows Remote Procedure Call RuntimeCVE-2021-28355Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportantWindows Remote Procedure Call RuntimeCVE-2021-28353Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportantWindows Remote Procedure Call RuntimeCVE-2021-28352Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportantWindows Remote Procedure Call RuntimeCVE-2021-28357Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportantWindows Remote Procedure Call RuntimeCVE-2021-28358Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportantWindows Remote Procedure Call RuntimeCVE-2021-28356Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportantWindows Remote Procedure Call RuntimeCVE-2021-28346Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportantWindows Remote Procedure Call RuntimeCVE-2021-28342Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportantWindows Remote Procedure Call RuntimeCVE-2021-28340Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportantWindows Remote Procedure Call RuntimeCVE-2021-28341Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportantWindows Remote Procedure Call RuntimeCVE-2021-28345Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportantWindows Remote Procedure Call RuntimeCVE-2021-28344Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportantWindows Remote Procedure Call RuntimeCVE-2021-28343Remote Procedure Call Runtime Remote Code Execution VulnerabilityCriticalWindows Resource ManagerCVE-2021-28320Windows Resource Manager PSM Service Extension Elevation of Privilege VulnerabilityImportantWindows Secure Kernel ModeCVE-2021-27090Windows Secure Kernel Mode Elevation of Privilege VulnerabilityImportantWindows Services and Controller AppCVE-2021-27086Windows Services and Controller App Elevation of Privilege VulnerabilityImportantWindows SMB ServerCVE-2021-28325Windows SMB Information Disclosure VulnerabilityImportantWindows SMB ServerCVE-2021-28324Windows SMB Information Disclosure VulnerabilityImportantWindows TCP/IPCVE-2021-28439Windows TCP/IP Driver Denial of Service VulnerabilityImportantWindows TCP/IPCVE-2021-28442Windows TCP/IP Information Disclosure VulnerabilityImportantWindows TCP/IPCVE-2021-28319Windows TCP/IP Driver Denial of Service VulnerabilityImportantWindows Win32KCVE-2021-27072Win32k Elevation of Privilege VulnerabilityImportantWindows Win32KCVE-2021-28310Win32k Elevation of Privilege VulnerabilityImportantWindows WLAN Auto Config ServiceCVE-2021-28316Windows WLAN AutoConfig Service Security Feature Bypass VulnerabilityImportant