Advisory Date: 14 April 2021

  DESCRIPTION

In the November 2020 Microsoft security patch release, Microsoft updated its vulnerability information page. Following the new patch information format, below are the CVEs that Trend Micro Cloud One Workload and Vulnerability Protection cover in the April 2021 release:

  • CVE-2021-28310 - Win32k Elevation of Privilege Vulnerability
    CVSS:3.0 7.8/7.2

  • CVE-2021-28325 - Windows SMB Information Disclosure Vulnerability
    CVSS:3.0 6.5/5.7

  INFORMATION EXPOSURE

Cloud One Workload and Deep Security shield networks through the following Deep Packet Inspection (DPI) rules. Trend Micro customers using the Vulnerability Protection are also protected from attacks using these vulnerabilities.

Vulnerability ID DPI Rule Number DPI Rule Name Release Date Vulnerability Protection Compatibility
CVE-2021-28325 1010900 Microsoft Windows SMB Information Disclosure Vulnerability (CVE-2021-28325) 13-Apr-21 YES
CVE-2021-28310 1010898 Microsoft Windows Win32k Elevation Of Privilege Vulnerability (CVE-2021-28310) 13-Apr-21 YES