⚠ Actively exploited
Added to CISA KEV on 2021-11-03. Federal agencies required to patch by 2021-11-17. Required action: Apply updates per vendor instructions..

CVE-2021-34448Out-of-bounds Write in Microsoft Windows 10 Version 1507

Severity
6.8MEDIUMCNA
CISA8.8
No vector
EPSS
2.0%
top 16.16%
CISA KEV
KEV
Added 2021-11-03
Due 2021-11-17
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJul 16
KEV addedNov 3
KEV dueNov 17
Latest updateApr 1
CISA Required Action: Apply updates per vendor instructions.

Description

Scripting Engine Memory Corruption Vulnerability Scripting Engine Memory Corruption Vulnerability

Affected Packages15 packages

CVEListV5microsoft/windows_76.1.06.1.7601.25661+1
CVEListV5microsoft/windows_8.16.3.06.3.9600.20069+1
CVEListV5microsoft/windows_server_20126.2.06.2.9200.23409+1
CVEListV5microsoft/windows_server_201610.0.010.0.14393.4530
CVEListV5microsoft/windows_server_201910.0.010.0.17763.2061

🔴Vulnerability Details

3
Project0
The More You Know, The More You Know You Don’t Know - Project Zero2022-04-01
CVEList
Scripting Engine Memory Corruption Vulnerability2021-07-16
VulnCheck
Microsoft Windows Scripting Engine Memory Corruption Vulnerability2021

📋Vendor Advisories

2
CISA
Microsoft Windows Scripting Engine Memory Corruption Vulnerability2021-11-03
Microsoft
Scripting Engine Memory Corruption Vulnerability2021-07-13

🕵️Threat Intelligence

2
Qualys
Microsoft and Adobe Patch Tuesday (July 2021) – Microsoft 117 Vulnerabilities with 13 Critical, Adobe 26 Vulnerabilities | Qualys2021-07-13
Qualys
Microsoft and Adobe Patch Tuesday (July 2021) – Microsoft 117 Vulnerabilities with 13 Critical, Adobe 26 Vulnerabilities2021-07-13
CVE-2021-34448 — Out-of-bounds Write in Microsoft | cvebase