-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
************************************************************************************
Title: Microsoft Security Update Revisions
Issued: April 12, 2022
************************************************************************************
Summary
=======
The following CVEs have undergone a revision increment.
====================================================================================
* CVE-2020-8927
- CVE-2022-8927 | Brotli Library Buffer Overflow Vulnerability
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-8927
- Version: 3.0
- Reason for Revision: The following changes were made: 1) Added Visual Studio 2022
version 17.1 to the Security Updates table as this version of Visual Studio is
affected by this vulnerability. Customers running this version of Visual Studio
2022 should install the April 2022 security updates to be protected from this
vulnerability. 2) Added Fixed Build Number to affected versions of .NET.
- Originally posted: March 8, 2022
- Updated: April 12, 2022
- Aggregate CVE Severity Rating: Important
* CVE-2021-43877
- CVE-2021-43877 | ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-43877
- Version: 2.0
- Reason for Revision: The following changes were made: 1) Added Visual Studio 2022
version 17.1 to the Security Updates table as this version of Visual Studio is
affected by this vulnerability. Customers running this version of Visual Studio
2022 should install the April 2022 security updates to be protected from this
vulnerability. 2) Corrected Article link.
- Originally posted: December 14, 2021
- Updated: April 12, 2022
- Aggregate CVE Severity Rating: Important
Other Information
=================
Recognize and avoid fraudulent email to Microsoft customers:
=============================================================
If you receive an email message that claims to be distributing a Microsoft security update, it is a hoax that may contain malware or pointers to malicious websites. Microsoft does not distribute security updates via email.