Patch Tuesday, October 2021 Edition
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-26427 | Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.0 | <1% |
| — | ||
| CVE-2021-30883 | Kernel Memory Corruption Zero-Day in Apple iOS, iPadOS, macOS, tvOS, watchOS CVE-2021-30883 is a memory corruption flaw (CWE-787, out-of-bounds write) in the kernel of Apple's iOS, iPadOS, macOS, tvOS, and watchOS, addressed with improved memory handling. It is triggered by a local application that mishandles memory, with the CVSS vector (AV:L, UI:R) indicating a user must run or interact with the malicious app. Successful exploitation allows arbitrary code execution with kernel privileges, giving an attacker full control over the affected device. All users of iPhones, iPads, Macs, Apple TVs, and Apple Watches running versions earlier than the patched releases are affected. Apple acknowledged the issue may have been actively exploited in the wild, and CISA added it to the KEV catalog; related reporting indicates it was among 2021 zero-days developed commercially and sold to government clients. Do: Upgrade iPhones and iPads to iOS/iPadOS 15.0.2 (or 14.8.1 for devices staying on iOS 14), Macs to macOS Monterey 12.0.1 or Big Sur 11.6.1, Apple TVs to tvOS 15.1, and Apple Watches to watchOS 8.1. As a CISA KEV entry, the required action is to apply updates per vendor instructions; inventory managed Apple devices and verify OS versions to confirm patching, prioritizing high-risk users who may have been targeted by commercial spyware. | 7.8 | 15% | KEV |
| mass≈1 billion+ Apple devices (iPhone/iPad/Mac/Apple TV/Apple Watch installed base running the affected OS versions) | |
| CVE-2021-36970 +1 in the same advisory: …40461 | Windows Print Spooler Spoofing Vulnerability Windows Print Spooler Spoofing Vulnerability NVD description · AI analysis pending | 8.8 group max | 3% |
| — | ||
| CVE-2021-38672 | Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.0 | 1% |
| — | ||
| CVE-2021-40449 | Use-After-Free Local Privilege Escalation in Microsoft Windows Win32k Microsoft's Win32k kernel driver contains a use-after-free (CWE-416) local privilege escalation vulnerability (CVE-2021-40449) affecting Windows client versions from Windows 7 through Windows 11 21H2. A local attacker who can already execute code on a system can trigger the flaw — demonstrated in a public proof of concept via the NtGdiResetDC system call — to corrupt kernel memory and elevate to SYSTEM-level privileges with high impact on confidentiality, integrity, and availability (CVSS 7.8, local vector, no user interaction). Any Windows desktop or laptop running the affected versions is exposed to any unprivileged process or malware that gains a foothold on the device. The bug was exploited as a zero-day in the wild before being fixed; CISA added it to the KEV catalog on 2021-11-17 with known ransomware use, and public reporting ties exploitation to the MysterySnail RAT campaign (including the lightweight MysteryMonoSnail backdoor). EPSS places the flaw in the 99th percentile, with a 74.1% probability of exploitation activity within 30 days. Do: Apply Microsoft's security updates addressing this Win32k flaw via Windows Update on all affected Windows 7, 8.1, 10, and 11 clients, per the CISA KEV required action, and verify inventories show no unpatched Windows 10 builds (1507–21H1) or Windows 11 21H2 endpoints. Because this was a zero-day exploited in the wild — including in campaigns involving MysterySnail and ransomware use noted by CISA — treat patching as urgent on all endpoints. Until patched, limit execution of untrusted or unprivileged local code on these systems. | 7.8 | 74% | KEV ransomware PoC |
| mass≈1 billion+ Windows client devices (effectively the entire Windows 7 through Windows 11 installed base at the time of disclosure) |
Full article896 words · extracted from krebsonsecurity.com · click to collapse
Microsoft today issued updates to plug more than 70 security holes in its Windows operating systems and other software, including one vulnerability that is already being exploited. This month’s Patch Tuesday also includes security fixes for the newly released Windows 11 operating system. Separately, Apple has released updates for iOS and iPadOS to address a flaw that is being actively attacked.

Firstly, Apple has released iOS 15.0.2 and iPadOS 15.0.2 to fix a zero-day vulnerability (CVE-2021-30883) that is being leveraged in active attacks targeting iPhone and iPad users. Lawrence Abrams of Bleeping Computer writes that the flaw could be used to steal data or install malware, and that soon after Apple patched the bug security researcher Saar Amar published a technical writeup and proof-of-concept exploit derived from reverse engineering Apple’s patch.
Abrams said the list of impacted Apple devices is quite extensive, affecting older and newer models. If you own an iPad or iPhone — or any other Apple device — please make sure it’s up to date with the latest security patches.
Three of the weaknesses Microsoft addressed today tackle vulnerabilities rated “critical,” meaning that malware or miscreants could exploit them to gain complete, remote control over vulnerable systems — with little or no help from targets.
One of the critical bugs concerns Microsoft Word, and two others are remote code execution flaws in Windows Hyper-V, the virtualization component built into Windows. CVE-2021-38672 affects Windows 11 and Windows Server 2022; CVE-2021-40461 impacts both Windows 11 and Windows 10 systems, as well as Server versions.
But as usual, some of the more concerning security weaknesses addressed this month earned Microsoft’s slightly less dire “important” designation, which applies to a vulnerability “whose exploitation could result in compromise of the confidentiality, integrity, or availability of user data, or of the integrity or availability of processing resources.”
The flaw that’s under active assault — CVE-2021-40449 — is an important “elevation of privilege” vulnerability, meaning it can be leveraged in combination with another vulnerability to let attackers run code of their choice as administrator on a vulnerable system.
CVE-2021-36970 is an important spoofing vulnerability in Microsoft’s Windows Print Spooler. The flaw was discovered by the same researchers credited with the discovery of one of two vulnerabilities that became known as PrintNightmare — the widespread exploitation of a critical Print Spooler flaw that forced Microsoft to issue an emergency security update back in July. Microsoft assesses CVE-2021-36970 as “exploitation more likely.”
“While no details have been shared publicly about the flaw, this is definitely one to watch for, as we saw a constant stream of Print Spooler-related vulnerabilities patched over the summer while ransomware groups began incorporating PrintNightmare into their affiliate playbook,” said Satnam Narang, staff research engineer at Tenable. “We strongly encourage organizations to apply these patches as soon as possible.”
CVE-2021-26427 is another important bug in Microsoft Exchange Server, which has been under siege lately from attackers. In March, threat actors pounced on four separate zero-day flaws in Exchange that allowed them to siphon email from and install backdoors at hundreds of thousands of organizations.
This month’s Exchange bug earned a CVSS score of 9.0 (10 is the most dangerous). Kevin Breen of Immersive Labs points out that Microsoft has marked this flaw as less likely to be exploited, probably because an attacker would already need access to your network before using the vulnerability.
“Email servers will always be prime targets, simply due to the amount of data contained in emails and the range of possible ways attackers could use them for malicious purposes. While it’s not right at the top of my list of priorities to patch, it’s certainly one to be wary of.”
Also today, Adobe issued security updates for a range of products, including Adobe Reader and Acrobat, Adobe Commerce, and Adobe Connect.
For a complete rundown of all patches released today and indexed by severity, check out the always-useful Patch Tuesday roundup from the SANS Internet Storm Center, and the Patch Tuesday data put together by Morphus Labs. And it’s not a bad idea to hold off updating for a few days until Microsoft works out any kinks in the updates: AskWoody.com frequently has the lowdown on any patches that are causing problems for Windows users.
On that note, before you update please make sure you have backed up your system and/or important files. It’s not uncommon for a Windows update package to hose one’s system or prevent it from booting properly, and some updates have been known to erase or corrupt files.
So do yourself a favor and backup before installing any patches. Windows 10 even has some built-in tools to help you do that, either on a per-file/folder basis or by making a complete and bootable copy of your hard drive all at once.
And if you wish to ensure Windows has been set to pause updating so you can back up your files and/or system before the operating system decides to reboot and install patches on its own schedule, see this guide.
If you experience glitches or problems installing any of these patches this month, please consider leaving a comment about it below; there’s a decent chance other readers have experienced the same and may chime in here with useful tips.
Text extracted automatically; images, tables and formatting may be missing. Original: https://krebsonsecurity.com/2021/10/patch-tuesday-october-2021-edition/