Analyst command view

MSRC Driver CVE Board

Latest-state board for filtered MSRC CVEs from 2020-01-01 to today, tuned for fast triage across module, CWE, release window, exploitation signal, and acknowledgement context.

Live snapshot
Last Sync
2026-05-20T07:39:30Z
Freshness
2 day(s) ago
Refresh Policy
24h baseline + release watch
Storage
Latest snapshot only
Rows In View
2109
Current result set after filter and search.
Exploited Flagged
1998
Rows with a non-empty exploitation signal.
Distinct CWE
1
Unique weakness classes in this view.
Modules
592
Unique inferred driver or component labels.
Reset
Active filters CWE Unspecified Clear filters

Top CWE

1 classes
Release Month
December 2021
8 CVE | last update 2 day(s) ago
Release 2021-12-14 Patch Tuesday Count 7
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-42293
Microsoft Jet Red Database Engine and Access Connectivity Engine
Exploitation Less Likely
Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2021-12-14 No
CVE-2021-43899
Microsoft 4K Wireless Display Adapter
Exploitation Less Likely
Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-12-14 No
Reported By
CVE-2021-41360
HEVC Video Extensions
Exploitation Less Likely
HEVC Video Extensions Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-12-14 No -
CVE-2021-40453
HEVC Video Extensions
Exploitation Less Likely
HEVC Video Extensions Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-12-14 No
Reported By
CVE-2021-40452
HEVC Video Extensions
Exploitation Less Likely
HEVC Video Extensions Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-12-14 No
Reported By
CVE-2021-43219
DirectX Graphics Kernel File
Exploitation Less Likely
DirectX Graphics Kernel File Denial of Service Vulnerability
CVSS vector: AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C
2021-12-14 No
Reported By
*HongZhenhao of Ant Group Light-Year Security Lab
CVE-2021-43225
Bot Framework SDK
Exploitation Less Likely
Bot Framework SDK Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
2021-12-14 No
Reported By
Terry Zhang @pnig0s
Release 2021-12-01 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2013-0340
expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function which allows remote attackers to cause a
No latest release note
expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function which allows remote attackers to cause a denial of service (resource consumption) send HTTP requests to intranet servers or read arbitrary files via a crafted XML document aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion the responsibility for resolving this issue lies with application developers; according to this argument this entry should be REJECTed and each affected application would need its own CVE.
No CVSS vector published
2021-12-01 - -
Release Month
November 2021
30 CVE | last update 2 day(s) ago
Release 2021-11-19 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-43976
In the Linux kernel through 5.15.2 mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a
No latest release note
In the Linux kernel through 5.15.2 mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic).
CVSS vector: AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2021-11-19 - -
Release 2021-11-16 Other / OOB Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-43211
Windows 10 Update Assistant
Exploitation Less Likely
Windows 10 Update Assistant Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2021-11-16 No
Reported By
Abdelhamid Naceri working with Trend Micro Zero Day Initiative
CVE-2021-42297
Windows 10 Update Assistant
Exploitation Less Likely
Windows 10 Update Assistant Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2021-11-16 No
Reported By
Abdelhamid Naceri working with Trend Micro Zero Day Initiative
Xuefeng Li and Zhiniang Peng with Sangfor
Release 2021-11-09 Patch Tuesday Count 27
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-41371
Windows Remote Desktop Protocol (RDP)
Exploitation Less Likely
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2021-11-09 No -
CVE-2021-38631
Windows Remote Desktop Protocol (RDP)
Exploitation Less Likely
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2021-11-09 No -
CVE-2021-41378
Windows NTFS
Exploitation Less Likely
Windows NTFS Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-11-09 No
Reported By
CVE-2021-42285
Windows Kernel
Exploitation Less Likely
Windows Kernel Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-11-09 No
Reported By
BugHunter010 (@CyberKunlun)
CVE-2021-41379
Windows Installer
Exploitation Less Likely
Windows Installer Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2021-11-09 No
Reported By
Abdelhamid Naceri working with Trend Micro Zero Day Initiative
CVE-2021-42274
Windows Hyper-V Discrete Device Assignment (DDA)
Exploitation Less Likely
Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability
CVSS vector: AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C
2021-11-09 No -
CVE-2021-42284
Windows Hyper-V
Exploitation Less Likely
Windows Hyper-V Denial of Service Vulnerability
CVSS vector: AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H/E:P/RL:O/RC:C
2021-11-09 No
Reported By
Maxime Villard, of M.O.R.S.E.
CVE-2021-42280
Windows Feedback Hub
Exploitation Less Likely
Windows Feedback Hub Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2021-11-09 No
Reported By
Abdelhamid Naceri working with Trend Micro Zero Day Initiative
CVE-2021-41377
Windows Fast FAT File System Driver
Exploitation Less Likely
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-11-09 No
Reported By
ZiMi (@YHZX_2013) with Alibaba Orion Security Lab
ziming zhang with Ant Security Light-Year Lab
CVE-2021-36957
Windows Desktop Bridge
Exploitation Less Likely
Windows Desktop Bridge Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-11-09 No
Reported By
Tao Yan (@Ga1ois) with Palo Alto Networks
CVE-2021-42286
Windows Core Shell SI Host Extension Framework for Composable Shell
Exploitation Less Likely
Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-11-09 No
Reported By
JIWO Technology Co., Ltd
CVE-2021-41356
Windows
Exploitation More Likely
Windows Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
2021-11-09 No -
CVE-2021-38665
Remote Desktop Protocol Client
Exploitation Less Likely
Remote Desktop Protocol Client Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
2021-11-09 No
Reported By
Valentino Ricotta with Thalium
CVE-2021-38666
Remote Desktop Client
Exploitation More Likely
Remote Desktop Client Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-11-09 No
Reported By
Valentino Ricotta with Thalium
CVE-2021-42283
NTFS
Exploitation Less Likely
NTFS Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-11-09 No
Reported By
Anonymous
CVE-2021-41370
NTFS
Exploitation Less Likely
NTFS Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-11-09 No
Reported By
HyungSeok Han with THEORI
JeongOh Kyea with THEORI
CVE-2021-41367
NTFS
Exploitation Less Likely
NTFS Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-11-09 No
Reported By
CVE-2021-42276
Microsoft Windows Media Foundation
Exploitation Less Likely
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-11-09 No
CVE-2021-26443
Microsoft Virtual Machine Bus (VMBus)
Exploitation Less Likely
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
CVSS vector: AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-11-09 No
Reported By
Wei in Kunlun lab
CVE-2021-42275
Microsoft COM for Windows
Exploitation Less Likely
Microsoft COM for Windows Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-11-09 No -
CVE-2021-41373
FSLogix
Exploitation Less Likely
FSLogix Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
2021-11-09 No -
CVE-2021-42277
Diagnostics Hub Standard Collector
Exploitation Less Likely
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2021-11-09 No
Reported By
Abdelhamid Naceri working with Trend Micro Zero Day Initiative
CVE-2021-41366
Credential Security Support Provider Protocol (CredSSP)
Exploitation Less Likely
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-11-09 No
Reported By
CVE-2021-42291
Active Directory Domain Services
Exploitation Less Likely
Active Directory Domain Services Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-11-09 No
Reported By
Andrew Bartlett of Catalyst IT
Lockheed Martin Red Team
CVE-2021-42287
Active Directory Domain Services
Exploitation Less Likely
Active Directory Domain Services Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-11-09 No
Reported By
Andrew Bartlett of Catalyst IT
CVE-2021-42282
Active Directory Domain Services
Exploitation Less Likely
Active Directory Domain Services Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-11-09 No
Reported By
Andrew Bartlett of Catalyst IT
CVE-2021-42278
Active Directory Domain Services
Exploitation Less Likely
Active Directory Domain Services Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-11-09 No
Reported By
Andrew Bartlett of Catalyst IT
Release Month
October 2021
12 CVE | last update 2 day(s) ago
Release 2021-10-26 Monthly Preview Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-35618
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial
No latest release note
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 1.8 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L).
CVSS vector: AV:A/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L
2021-10-26 - -
Release 2021-10-12 Patch Tuesday Count 11
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-38663
Windows exFAT File System
Exploitation Less Likely
Windows exFAT File System Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2021-10-12 No
Reported By
OldStone of Kunlun Lab
CVE-2021-40465
Windows Text Shaping
Exploitation Less Likely
Windows Text Shaping Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-10-12 No
Reported By
CVE-2021-36953
Windows TCP/IP
Exploitation Less Likely
Windows TCP/IP Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2021-10-12 No
CVE-2021-41332
Windows Print Spooler
Exploitation Less Likely
Windows Print Spooler Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2021-10-12 No
Reported By
Liubenjin with Codesafe Team of Legendsec at Qi'anxin Group
CVE-2021-40463
Windows Network Address Translation (NAT)
Exploitation Less Likely
Windows Network Address Translation (NAT) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C
2021-10-12 No
CVE-2021-40464
Windows Nearby Sharing
Exploitation Less Likely
Windows Nearby Sharing Elevation of Privilege Vulnerability
CVSS vector: AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-10-12 No
Reported By
Caleb Helbling
CVE-2021-40462
Windows Media Foundation Dolby Digital Atmos Decoders
Exploitation Less Likely
Windows Media Foundation Dolby Digital Atmos Decoders Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-10-12 No
Reported By
HAO LI of VenusTech ADLab
CVE-2021-41331
Windows Media Audio Decoder
Exploitation Less Likely
Windows Media Audio Decoder Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2021-10-12 No
Reported By
HAO LI of VenusTech ADLab
CVE-2021-41342
Windows MSHTML Platform
Exploitation Less Likely
Windows MSHTML Platform Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C
2021-10-12 No
Reported By
CVE-2021-41336
Windows Kernel
Exploitation Less Likely
Windows Kernel Information Disclosure Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2021-10-12 No
Reported By
Kyle Westhaus working with Microsoft Security Assurance & Vulnerability Research
CVE-2021-41335
Windows Kernel
Exploitation Less Likely
Windows Kernel Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
2021-10-12 No
Reported By
Prev Page 16 / 43 | rows 751-800 of 2109 Next