Microsoft Patch Tuesday for June 2021 — Snort rules and prominent vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-28550 | Use-After-Free RCE in Adobe Acrobat and Reader CVE-2021-28550 is a use-after-free memory corruption flaw in Adobe Acrobat DC and Acrobat Reader DC that an unauthenticated attacker can trigger by getting a victim to open a malicious PDF file. Successful exploitation allows arbitrary code execution in the context of the current user, giving the attacker the privileges of that user on the affected machine. Anyone running Acrobat or Acrobat Reader DC at or below versions 2021.001.20150, 2020.001.30020, or 2017.011.30194 is affected. The flaw was exploited as a zero-day in targeted attacks — Microsoft reported it being chained with Windows zero-days by an Austrian company's operators — and it is listed in CISA's Known Exploited Vulnerabilities catalog as of November 3, 2021. CISA's required action is to apply vendor updates, and defenders should treat exploited, user-targeted PDF attacks as the primary risk. Do: Upgrade Acrobat and Acrobat Reader DC to versions later than 2021.001.20150, 2020.001.30020, and 2017.011.30194 on the respective tracks, per Adobe's May 2021 update and the CISA KEV required action. Until patched, avoid opening PDFs from untrusted sources and consider email-gateway filtering or sandboxing of PDF attachments. Check endpoint inventory for the affected version ranges and prioritize systems of users who handle unsolicited documents. | 8.8 | 52% | KEV |
| masshundreds of millions of installations (Acrobat Reader is the world's most widely deployed PDF viewer) | |
| CVE-2021-31199 +1 in the same advisory: …31201 | Elevation of Privilege in Microsoft Enhanced Cryptographic Provider (Windows) CVE-2021-31199 is an elevation-of-privilege vulnerability in the Microsoft Enhanced Cryptographic Provider, a core Windows component that provides cryptographic services to applications. It carries a CVSS 3.1 score of 5.2 (AV:L/AC:L/PR:L/UI:N/S:C), meaning it is triggered by an attacker who already runs low-privileged code locally on a vulnerable Windows system, with no user interaction required, and lets the attacker break out of the intended security scope to gain elevated privileges. The gain is higher privileges on the compromised host, typically used as a stepping stone in a broader intrusion or malware delivery chain. Exposure is broad: any unpatched Windows 7, 8.1, RT 8.1, Windows 10 (versions 1507 through 21H1), Windows Server 2008, or Windows Server 2004 system is affected, since the provider ships with Windows itself. Exploitation is confirmed in the wild: it was one of the actively exploited Windows zero-days fixed in Microsoft's mid-2021 Patch Tuesday release (part of the six/seven-zero-day coverage), Microsoft attributed targeted attacks to the Austrian firm DSIRF using its Subzero surveillance malware, and the flaw was added to CISA's KEV on 2021-11-03; EPSS estimates a 3.0% chance of exploitation in the next 30 days (86th percentile) and no public PoC is known. Do: Apply Microsoft's security updates (the monthly Patch Tuesday cumulative updates covering this CVE) per vendor instructions for every in-scope Windows version — the flaw is in CISA KEV, so patching is mandatory for federal agencies and there is no documented workaround. Verify hosts have received the updated cumulative update, prioritizing multi-user endpoints, RDP/terminal servers, and workstations where untrusted code runs; if patching is delayed, hunt for signs of targeted intrusion consistent with DSIRF/Subzero activity. | 5.2 | 3% | KEV |
| mass≈1 billion+ Windows devices (Windows 10 alone had over 1 billion active devices, and the affected set also includes Windows 7/8.1/RT 8.1 and Windows Server… | |
| CVE-2021-31939 | Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability NVD description · AI analysis pending | 7.8 | 13% |
| — | ||
| CVE-2021-33739 +1 in the same advisory: …31955 | Privilege Escalation in Microsoft Windows Desktop Window Manager (DWM) Core Library CVE-2021-33739 is an elevation-of-privilege vulnerability in the Microsoft Desktop Window Manager (DWM) Core Library, the component that composites the Windows graphical desktop. A local attacker who can already execute code on a vulnerable machine — for example via a malicious application, an Office payload, or a chained remote code execution bug — can exploit the flaw in DWM to gain elevated privileges on the system. Successful exploitation yields high-impact results (CVSS 8.4, high for confidentiality, integrity and availability), and the bug is typically used to break out of a low-privileged context or complete a full compromise chain. Affected systems are Windows 10 versions 1909, 2004, 20H2 and 21H1, and Windows Server versions 2004 and 20H2, prior to the June 2021 security updates. The flaw was one of six zero-days Microsoft confirmed as actively exploited in the June 2021 Patch Tuesday release; it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 and carries a 6.6% EPSS (93rd percentile), although no public PoC is known and ransomware use is undetermined. Do: Apply the June 2021 (or later) Windows cumulative updates on Windows 10 1909/2004/20H2/21H1 and Windows Server 2004/20H2, consistent with CISA's required action to apply vendor updates. Because this is a local privilege escalation, prioritize hosts where untrusted or multi-user code runs (VDI, RDS, kiosks, jump servers) and environments with KEV-mandated remediation deadlines. Verify patch status against the June 2021 release, since the bug was confirmed exploited in the wild. | 8.4 group max | 7% | KEV |
| masshundreds of millions of endpoints (Windows 10's installed base exceeds 1 billion devices; builds 1909 through 21H1 were the dominant Windows 10 releases in… | |
| CVE-2021-31985 | Microsoft Defender Remote Code Execution Vulnerability Microsoft Defender Remote Code Execution Vulnerability NVD description · AI analysis pending | 7.8 | 8% |
| — |
Full article597 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, June 8, 2021 13:43
By Jon Munshaw, with contributions from Edmund Brumaghin.
Microsoft released its monthly security update Tuesday, disclosing 51 vulnerabilities across its suite of products, breaking last month’s 16-month record of the fewest vulnerabilities disclosed in a month by the company.
There are only four critical vulnerabilities patched in this month, while all the other ones are considered “important.” However, there are several vulnerabilities that Microsoft states are being actively exploited in the wild.
This month’s security update provides updates for several pieces of software and Windows functions, including SharePoint Server, the Windows kernel and Outlook. For a full rundown of these CVEs, head to Microsoft’s security update page. Two of the vulnerabilities Microsoft disclosed today are related to a separate vulnerability in Adobe Acrobat Reader. Microsoft released fixes for CVE-2021-31199 and CVE-2021-31201 in its Enhanced Cryptographic Provider. An attacker could elevate their privileges on the targeted system if they trick a user into opening a specially crafted PDF file in a vulnerable version of Adobe Acrobat or Adobe Reader while the software is running on an affected version of Windows. Microsoft stated in its advisories that it’s seen these vulnerabilities be exploited in the wild.
Adobe also addressed this issue in their monthly security update in May, releasing a patch for CVE-2021-28550. Users are encouraged to update affected versions of Windows and Adobe Acrobat to protect themselves from the exploitation of these vulnerabilities.
One of the critical vulnerabilities this month exists in the Windows Defender anti-malware software. CVE-2021-31985 could allow an attacker to execute remote code on the targeted machine. However, Microsoft stated the vulnerability, along with others identified in Windows Defender this month, will be updated automatically. Users can verify the update was downloaded and installed by verifying steps Microsoft outlined in its advisory.
CVE-2021-31939 is another remote code execution vulnerability. An attacker could exploit this vulnerability in Microsoft Office’s MSGraph component to deliver a malicious payload to the victim machine without any special functions, as this component is embedded in most Microsoft Office documents. Checkpoint first disclosed this vulnerability Tuesday.
Because the component can be embedded in most Office documents, an attacker can use it to deliver a malicious payload without the need for special functions.
Another vulnerability, a privilege escalation flaw in the DWM Core Library, has already been exploited in the wild, according to Microsoft. An attacker could trigger CVE-2021-33739 by running an executable or script on the local machine. Although this vulnerability has a CVSS score of 8.4 out of 10, Microsoft still considers it to be “important.”
Talos would also like to specifically highlight CVE-2021-31955, which an attacker could exploit to read the contents of Kernel memory from a user-mode process. Microsoft stated in its advisory that this vulnerability has also been actively exploited in the wild already.
A complete list of all the vulnerabilities Microsoft disclosed this month is available on its update page.
In response to these vulnerability disclosures, Talos is releasing a new SNORTⓇ rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Firepower customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.
The rules included in this release that protect against the exploitation of many of these vulnerabilities are 49388, 49389, 57722 - 57727, 57730 - 57733, 57735 and 57736.
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-for-june-2021/