5.5

CVE-2021-40454

Rich Text Edit Control Information Disclosure Vulnerability

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft365 Apps Version- SwEditionenterprise HwPlatformx64
Microsoft365 Apps Version- SwEditionenterprise HwPlatformx86
MicrosoftOffice Version2013 Updatesp1 HwPlatformx64
MicrosoftOffice Version2013 Updatesp1 HwPlatformx86
MicrosoftOffice Version2013_rt Updatesp1
MicrosoftOffice Version2016 HwPlatformx64
MicrosoftOffice Version2016 HwPlatformx86
MicrosoftOffice Version2019 HwPlatformx64
MicrosoftOffice Version2019 HwPlatformx86
MicrosoftOffice Version2019 SwPlatformmacos
MicrosoftOffice Version2021 Editionltsc SwPlatformmacos
MicrosoftOffice Version2021 Editionltsc SwPlatformx64
MicrosoftOffice Version2021 Editionltsc SwPlatformx86
MicrosoftWindows 10 Version- HwPlatformx64
MicrosoftWindows 10 Version- HwPlatformx86
MicrosoftWindows 10 Version20h2 HwPlatformarm64
MicrosoftWindows 10 Version20h2 HwPlatformx64
MicrosoftWindows 10 Version20h2 HwPlatformx86
MicrosoftWindows 10 Version21h1 HwPlatformarm64
MicrosoftWindows 10 Version21h1 HwPlatformx64
MicrosoftWindows 10 Version21h1 HwPlatformx86
MicrosoftWindows 10 Version1607 HwPlatformx64
MicrosoftWindows 10 Version1607 HwPlatformx86
MicrosoftWindows 10 Version1809 HwPlatformarm64
MicrosoftWindows 10 Version1809 HwPlatformx64
MicrosoftWindows 10 Version1809 HwPlatformx86
MicrosoftWindows 10 Version1909 HwPlatformarm64
MicrosoftWindows 10 Version1909 HwPlatformx64
MicrosoftWindows 10 Version1909 HwPlatformx86
MicrosoftWindows 10 Version2004 HwPlatformarm64
MicrosoftWindows 10 Version2004 HwPlatformx64
MicrosoftWindows 10 Version2004 HwPlatformx86
MicrosoftWindows 11 Version- HwPlatformarm64
MicrosoftWindows 11 Version- HwPlatformx64
MicrosoftWindows 8.1 Version- HwPlatformx64
MicrosoftWindows 8.1 Version- HwPlatformx86
MicrosoftWindows Rt 8.1 Version-
MicrosoftWindows Server Version20h2
MicrosoftWindows Server Version2004
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.354
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
secure@microsoft.com 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-312 Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.