Microsoft Issues Windows Update to Patch 0
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-43217 | Windows Encrypting File System (EFS) Remote Code Execution Vulnerability Windows Encrypting File System (EFS) Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.8 group max | 6% |
| — | ||
| CVE-2021-42309 | Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.8 | 3% |
| — | ||
| CVE-2021-43880 | Windows Mobile Device Management Elevation of Privilege Vulnerability Windows Mobile Device Management Elevation of Privilege Vulnerability NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2021-43890 | Spoofing Vulnerability in Microsoft Windows AppX Installer Actively Exploited CVE-2021-43890 is a spoofing vulnerability in the AppX Installer (App Installer) component of Microsoft Windows that allows a specially crafted package to masquerade as a trusted application. Triggering it requires user interaction: an attacker distributes a malicious installer package or ms-appinstaller link, typically via phishing, and must convince the user to open it, with impact limited to the privileges of the affected account. Successful exploitation delivers malware — Microsoft observed the Emotet, Trickbot and BazaLoader families in these attacks — and the flaw has also been used in ransomware campaigns, with users operating with administrative rights facing greater impact than low-privileged users. Essentially any Windows system relying on App Installer is affected; the exact affected build ranges are not enumerated in the advisory data, though contemporaneous headlines characterized it as an actively exploited Windows 10 zero-day addressed in the December 2021 Patch Tuesday. Exploitation is confirmed in the wild: CISA added it to KEV on 2021-12-15 with known ransomware use (EPSS 10.3% / 95th percentile), and in late 2023 Microsoft Threat Intelligence reported renewed abuse of the ms-appinstaller URI scheme and disabled that protocol by default in the updated App Installer. Do: Apply Microsoft's security updates per the vendor advisory (December 2021 Windows updates) and install the updated App Installer using the Microsoft Store links in the advisory. Verify the updated App Installer is in place and that the ms-appinstaller protocol handler is disabled — it is disabled by default in the December 27, 2023 App Installer update. Because exploitation depends on users opening crafted packages, prioritize patching systems where users run with administrative rights and remind users to treat app-installer links and attachments arriving via email or chat with caution. | 7.1 | 10% | KEV ransomware PoC |
| mass~1 billion+ Windows devices (App Installer ships as a built-in Windows component) | |
| CVE-2021-43899 | Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2021-43905 | Microsoft Office app Remote Code Execution Vulnerability Microsoft Office app Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.6 | 3% |
| — | ||
| CVE-2021-43907 | Visual Studio Code WSL Extension Remote Code Execution Vulnerability Visual Studio Code WSL Extension Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.8 | 4% |
| — |
Full article546 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananDec 15, 2021
Microsoft has rolled out Patch Tuesday updates to address multiple security vulnerabilities in Windows and other software, including one actively exploited flaw that's being abused to deliver Emotet, TrickBot, or Bazaloader malware payloads.
The latest monthly release for December fixes a total of 67 flaws, bringing the total number of bugs patched by the company this year to 887, according to the Zero Day Initiative. Seven of the 67 flaws are rated Critical and 60 are rated as Important in severity, with five of the issues publicly known at the time of release. It's worth noting that this is in addition to the 21 flaws resolved in the Chromium-based Microsoft Edge browser.
The most critical of the lot is CVE-2021-43890 (CVSS score: 7.1), a Windows AppX installer spoofing vulnerability that Microsoft said could be exploited to achieve arbitrary code execution. The lower severity rating is indicative of the fact that code execution hinges on the logged-on user level, meaning "users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights."
The Redmond-based tech giant noted that an adversary could leverage the flaw by crafting a malicious attachment that's then used as part of a phishing campaign to trick the recipients into opening the email attachment. Sophos security researchers Andrew Brandt as well as Rick Cole and Nick Carr of the Microsoft Threat Intelligence Center (MSTIC) have been credited with reporting the vulnerability.
"Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/ Trickbot/ Bazaloader," the company further added. The development comes as Emotet malware campaigns are witnessing a surge in activity after more than a 10-month-long hiatus following a coordinated law enforcement effort to disrupt the botnet's reach.
Other flaws that are publicly known are below —
- CVE-2021-43240 (CVSS score: 7.8) - NTFS Set Short Name Elevation of Privilege Vulnerability
- CVE-2021-43883 (CVSS score: 7.8) - Windows Installer Elevation of Privilege Vulnerability
- CVE-2021-41333 (CVSS score: 7.8) - Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2021-43893 (CVSS score: 7.5) - Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability
- CVE-2021-43880 (CVSS score: 5.5) - Windows Mobile Device Management Elevation of Privilege Vulnerability
The December patch also comes with remediations for 10 remote code execution flaws in Defender for IoT, in addition to critical bugs affecting iSNS Server (CVE-2021-43215), 4K Wireless Display Adapter (CVE-2021-43899), Visual Studio Code WSL Extension (CVE-2021-43907), Office app (CVE-2021-43905), Windows Encrypting File System (CVE-2021-43217), Remote Desktop Client (CVE-2021-43233), and SharePoint Server (CVE-2021-42309).
Software Patches From Other Vendors
Besides Microsoft, security updates have also been released by other vendors to rectify several vulnerabilities, including —
- Adobe
- Android
- Apple
- Cisco
- Citrix
- Intel
- Linux distributions Oracle Linux, Red Hat, and SUSE
- SAP
- Schneider Electric, and
- Siemens
Furthermore, numerous security advisories have been released by dozens of companies for the actively exploited Log4j remote code execution vulnerability that could allow a complete takeover of affected systems.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/12/microsoft-issues-windows-update-to.html