In the November 2020 Microsoft security patch release, Microsoft updated its vulnerability information page. Following the new patch information format, below are some of the CVEs included in the October 2021 release:
CVE-2021-38672 - Windows Hyper-V Remote Code Execution Vulnerability CVSS:3.1 8.0/7.0
CVE-2021-40461 - Windows Hyper-V Remote Code Execution Vulnerability CVSS:3.1 8.0/7.0
CVE-2021-40486 - Microsoft Word Remote Code Execution Vulnerability CVSS:3.0 7.8/6.8
Our two-year research provides insights into the life cycle of exploits, the types of exploit buyers and sellers, and the business models that are reshaping the underground exploit market.
Malicious attacks have consistently been launched on weak points in the supply chain. Like all attacks, these will evolve into more advanced forms. Software development, with multiple phases that could be placed at risk, is particularly vulnerable.