ZeroHour
Cisco Talospublished ()ingested

Microsoft Patch Tuesday for Oct. 2021 — Snort rules and prominent vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-26427
Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.0<1%
  • microsoft exchange server
CVE-2021-36970
+2 in the same advisory: …40461 …41332
Windows Print Spooler Spoofing Vulnerability

Windows Print Spooler Spoofing Vulnerability

NVD description · AI analysis pending
8.8
group max
3%
  • microsoft windows 10
  • microsoft windows 11
  • microsoft windows 7
  • +1 more
CVE-2021-38672
Windows Hyper-V Remote Code Execution Vulnerability

Windows Hyper-V Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.01%
  • microsoft windows 11
  • microsoft windows server 2022
CVE-2021-40449
Use-After-Free Local Privilege Escalation in Microsoft Windows Win32k

Microsoft's Win32k kernel driver contains a use-after-free (CWE-416) local privilege escalation vulnerability (CVE-2021-40449) affecting Windows client versions from Windows 7 through Windows 11 21H2. A local attacker who can already execute code on a system can trigger the flaw — demonstrated in a public proof of concept via the NtGdiResetDC system call — to corrupt kernel memory and elevate to SYSTEM-level privileges with high impact on confidentiality, integrity, and availability (CVSS 7.8, local vector, no user interaction). Any Windows desktop or laptop running the affected versions is exposed to any unprivileged process or malware that gains a foothold on the device. The bug was exploited as a zero-day in the wild before being fixed; CISA added it to the KEV catalog on 2021-11-17 with known ransomware use, and public reporting ties exploitation to the MysterySnail RAT campaign (including the lightweight MysteryMonoSnail backdoor). EPSS places the flaw in the 99th percentile, with a 74.1% probability of exploitation activity within 30 days.

Do: Apply Microsoft's security updates addressing this Win32k flaw via Windows Update on all affected Windows 7, 8.1, 10, and 11 clients, per the CISA KEV required action, and verify inventories show no unpatched Windows 10 builds (1507–21H1) or Windows 11 21H2 endpoints. Because this was a zero-day exploited in the wild — including in campaigns involving MysterySnail and ransomware use noted by CISA — treat patching as urgent on all endpoints. Until patched, limit execution of untrusted or unprivileged local code on these systems.

7.874% KEV ransomware PoC
  • Microsoft Windows 10 1507, 1607, 1809, 1909, 2004, 20H2, 21H1
  • Microsoft Windows 11 21H2
  • Microsoft Windows 7 7
  • +2 more
mass≈1 billion+ Windows client devices (effectively the entire Windows 7 through Windows 11 installed base at the time of disclosure)
CVE-2021-40450
+1 in the same advisory: …41357
Local Privilege Escalation in Microsoft Win32k (Windows 10/11 and Windows Server)

CVE-2021-40450 is an elevation-of-privilege vulnerability in Win32k, the Windows kernel-mode graphics/window-manager subsystem, affecting Windows 10 (builds 1809 through 21H1), Windows 11 21H2, and Windows Server 2019, 2004, 20H2, and 2022. It is triggered locally: per the CVSS vector (AV:L/PR:L/UI:N), an attacker must already be able to execute code on the target as a low-privileged user, with no user interaction required, and then abuses the Win32k flaw to escalate. Successful exploitation yields SYSTEM-level privileges, giving full control of the host (reading or modifying any data, installing software, disabling security controls), and such flaws are commonly chained with an initial remote-code-execution or phishing foothold to fully compromise a machine. Any organization or individual running the affected Windows builds is exposed in principle, though practical risk concentrates on hosts where an attacker can first gain a local foothold. The flaw was addressed in Microsoft's October 2021 Patch Tuesday; it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-25, confirming in-the-wild exploitation (no public PoC is known, EPSS estimates roughly 2.1% probability of exploitation in the next 30 days, and any ransomware association is unconfirmed).

Do: Apply Microsoft's October 2021 security updates (per vendor instructions) to all affected Windows 10, Windows 11, and Windows Server hosts, prioritizing endpoints exposed to untrusted users and servers where an attacker could chain this elevation with a remote-code-execution or phishing foothold. Because the flaw is KEV-listed with confirmed in-the-wild exploitation, verify installed patch/build levels across the estate and check hosts with any indicators of compromise for local privilege-escalation activity; if patching is delayed, limit local code execution by untrusted users and monitor for suspicious SYSTEM-level process activity.

7.82% KEV
  • Microsoft Windows 10 1809, 1909, 2004, 20H2, 21H1
  • Microsoft Windows 11 21H2
  • Microsoft Windows Server 2019, 2004, 20H2, 2022
masshundreds of millions of Windows endpoints (Windows 10/11 desktops and Windows Server hosts on the affected builds)
CVE-2021-40474
Microsoft Excel Remote Code Execution Vulnerability

Microsoft Excel Remote Code Execution Vulnerability

NVD description · AI analysis pending
7.82%
  • microsoft 365 apps
  • microsoft excel
  • microsoft office
  • +1 more
Full article514 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, October 12, 2021 13:33

By Jon Munshaw, with contributions from Asheer Malhotra.

Microsoft released its monthly security update Tuesday, disclosing 78 vulnerabilities in the company’s various software, hardware and firmware offerings.

This month’s release is particularly notable because there are only two critical vulnerabilities included, with the rest being important. This is the fewest number of critical vulnerabilities disclosed as part of a Patch Tuesday in at least a year.

CVE-2021-40461 is one of the critical vulnerabilities — a flaw in the Network Virtualization Service Provider that could allow an attacker to execute remote code on the target machine. This vulnerability has a severity rating of 9.9 out of a possible 10, virtually the highest severity rating seen in Patch Tuesdays.

The other critical vulnerability, CVE-2021-38672, exists in Windows Hyper-V. This vulnerability could also lead to remote code execution and has the same severity score as CVE-2021-40461.  One of the issues disclosed this month has been exploited in the wild: CVE-2021-40449. This vulnerability in the Win32k process requires no user interaction and could allow an attacker to obtain elevated privileges on the targeted machine. There are two other Win32k vulnerabilities in this month’s Patch Tuesday, though neither has been exploited in the wild as of yet: CVE-2021-40450 and CVE-2021-41357.

And on the heels of PrintNightmare, Microsoft is closing two new vulnerabilities in its print spooler service: CVE-2021-36970 and CVE-2021-41332. CVE-2021-36970 is the most serious of the group, with a severity rating of 8.8. An attacker could exploit this vulnerability to carry out a spoofing attack. Although there is currently no additional information available on this vulnerability, a spoofing attack usually allows an adversary to identify as another legitimate user or program by falsifying data.

Talos researchers discovered one of the important vulnerabilities: TALOS-2021-1259 (CVE-2021-40474), a remote code execution vulnerability in Microsoft Excel. You can read more about this issue in our full Vulnerability Spotlight post.

Lastly, since other high-profile attacks on Microsoft Exchange Servers have been in the headlines recently, we also wanted to highlight CVE-2021-26427. This vulnerability is considered “less likely” to be exploited by Microsoft, but could still allow an attacker to execute remote code on the targeted server. Exchange Server was recently the target of a high-profile attack from the previously unknown Hafnium threat actor.

A complete list of all the vulnerabilities Microsoft disclosed this month is available on its update page.

In response to these vulnerability disclosures, Talos is releasing a new SNORTⓇ rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Cisco Secure Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.

The rules included in this release that protect against the exploitation of many of these vulnerabilities are 58286 - 58289, 58294, 58295 and 58303 - 58319.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-for-oct-2021/