CVE-2021-26859HighCVSS 7.7
Microsoft Power BI Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What type of information could be disclosed by this vulnerability? Exploiting this vulnerability could allow the disclosure of NTLM hashes.
🎯 Affected products2
- Power BI Report Server version 15.0.1103.234
- Power BI Report Server version 15.0.1104.300
✅ Remediation
KB5001284 (Security Update) — fixed build 1.8.7485.35104 KB5001285 (Security Update) — fixed build 1.9.7675.15620
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26859
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=56722
- referencehttps://support.microsoft.com/help/5001284
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=57270
- referencehttps://support.microsoft.com/help/5001285