CVE-2021-34448: Scripting Engine Memory Corruption Vulnerability
Published Jul 13, 2021
·Updated
Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption.
Other sources
Scripting Engine Memory Corruption Vulnerability
— NVD
Affected Software
53 affected componentsFixes available
Microsoft Windows 10
Microsoft Windows 10=20h2
Microsoft Windows 10=21h1
Microsoft Windows 10=1607
Microsoft Windows 10=1809
Microsoft Windows 10=1909
Microsoft Windows 10=2004
Microsoft Windows 7=sp1
Microsoft Windows 8.1
Microsoft Windows RT 8.1
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft Windows
Microsoft Windows 10 1507<10.0.10240.19003
Microsoft Windows 10 1607<10.0.14393.4530
Microsoft Windows 10 1809<10.0.17763.2061
Microsoft Windows 10 1909<10.0.18363.1679
Microsoft Windows 10 2004<10.0.19041.1110
Microsoft Windows 10 20h2<10.0.19042.1110
Microsoft Windows 10 21h1<10.0.19043.1110
Microsoft Windows Server 2016<10.0.14393.4530
Microsoft Windows Server 2019<10.0.17763.2061
Microsoft Windows 10=1607
10.0.14393.4530
Microsoft Windows 10=2004
10.0.19041.1110
Microsoft Windows 10=20H2
10.0.19042.1110
Microsoft Windows 10<10.0.10240.19003
10.0.10240.19003
Microsoft Windows 10=21H1
10.0.19043.1110
Microsoft Windows 10<10.0.10240.19003
10.0.10240.19003
Microsoft Windows Server 2012 R2<6.3.9600.20069, <1.001
6.3.9600.200691.001
Microsoft Windows 10=20H2
10.0.19042.1110
Microsoft Windows 10=21H1
10.0.19043.1110
Microsoft Windows 10=2004
10.0.19041.1110
Microsoft Windows 10=2004
10.0.19041.1110
Microsoft Windows 10=1909
10.0.18363.1679
Microsoft Windows 10=21H1
10.0.19043.1110
Microsoft Windows 10=1909
10.0.18363.1679
Microsoft Windows Server 2012<6.2.9200.23409, <1.001
6.2.9200.234091.001
Microsoft Windows 10=1909
10.0.18363.1679
Microsoft Windows RT 8.1<6.3.9600.20069
6.3.9600.20069
Microsoft Windows Server 2019<10.0.17763.2061
10.0.17763.2061
Microsoft Windows 8.1 for x64-based systems<6.3.9600.20069, <1.001
6.3.9600.200691.001
Microsoft Windows Server 2008 R2<6.1.7601.25661, <1.001
6.1.7601.256611.001
Microsoft Windows 10=1607
10.0.14393.4530
Microsoft Windows 7<6.1.7601.25661, <1.001
6.1.7601.256611.001
Microsoft Windows 7<6.1.7601.25661, <1.001
6.1.7601.256611.001
Microsoft Windows 8.1 for 32-bit systems<6.3.9600.20069, <1.001
6.3.9600.200691.001
Microsoft Windows Server 2016<10.0.14393.4530
10.0.14393.4530
Microsoft Windows 10=1809
10.0.17763.2061
Microsoft Windows 10=1809
10.0.17763.2061
Microsoft Windows 10=1809
10.0.17763.2061
Remediation
Event History
Jul 13, 2021
CVE Published
via Microsoft·02:00 PM
Known Exploited
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
Jul 16, 2021
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
DescriptionSeverity
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-34448?
The severity of CVE-2021-34448 has been assessed as important due to its potential for memory corruption.
2
How do I fix CVE-2021-34448?
To fix CVE-2021-34448, apply the latest security updates from Microsoft for affected Windows versions.
3
What systems are affected by CVE-2021-34448?
CVE-2021-34448 affects various versions of Microsoft Windows, including Windows 7, Windows 10, and Windows Server.
4
What type of vulnerability is CVE-2021-34448?
CVE-2021-34448 is classified as a memory corruption vulnerability within the Microsoft Windows Scripting Engine.
5
Can CVE-2021-34448 lead to remote code execution?
Yes, CVE-2021-34448 could potentially allow attackers to execute arbitrary code through exploitation.