ZeroHour
Cisco Talospublished ()ingested

Microsoft Patch Tuesday for August 2021 — Snort rules and prominent vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-26424
+1 in the same advisory: …26432
Windows TCP/IP Remote Code Execution Vulnerability

Windows TCP/IP Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.9
group max
61%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2021-26430
+1 in the same advisory: …26428
Azure Sphere Denial of Service Vulnerability

Azure Sphere Denial of Service Vulnerability

NVD description · AI analysis pending
6.0
group max
<1%
  • microsoft azure sphere
CVE-2021-34535
Remote Desktop Client Remote Code Execution Vulnerability

Remote Desktop Client Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.822%
  • microsoft remote desktop client
  • microsoft windows 10
  • microsoft windows 7
  • +1 more
CVE-2021-36942
Unauthenticated LSA Spoofing (PetitPotam NTLM Relay) in Microsoft Windows

CVE-2021-36942 is a spoofing flaw in the Windows Local Security Authority (LSA), widely known as "PetitPotam," that lets an unauthenticated network attacker trick a Windows host into authenticating with NTLM to a machine the attacker controls. It is triggered remotely with no privileges and no user interaction (CVSS 3.1 AV:N/AC:L/PR:N/UI:N) by sending crafted requests that coerce the target system to authenticate. By relaying that coerced authentication to other services, an attacker can impersonate the machine — most critically a domain controller — and escalate toward domain-administrator access, producing a high confidentiality impact. All listed Windows Server releases are affected, with domain controllers and certificate-services servers as the highest-value targets. The flaw is actively exploited in the wild: it was added to CISA's KEV on 2021-11-03 with known ransomware use (LockFile and Babuk campaigns chained it with Exchange flaws), and Microsoft has released Windows updates to address it.

Do: Apply Microsoft's Windows updates per vendor instructions, prioritizing domain controllers and servers running Active Directory Certificate Services. As interim hardening, require SMB signing and restrict NTLM authentication per Microsoft guidance, and review authentication logs for unexpected NTLM connections from domain controllers to certificate-services endpoints.

7.566% KEV ransomware PoC
  • Microsoft Windows (per CISA affected listing) as listed by CISA
  • Microsoft Windows Server 2004 as listed in CISA/CPE data
  • Microsoft Windows Server 2008 as listed in CISA/CPE data
  • +4 more
massmillions of Windows Server deployments; hundreds of thousands of SMB-exposed hosts in public internet scans
Full article556 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, August 10, 2021 13:36

By Jon Munshaw, with contributions from Martin Lee.

Microsoft released its monthly security update Tuesday, disclosing 44 vulnerabilities in the company’s firmware and software. This is the fewest amount of vulnerabilities Microsoft has patched in a month in more than two years.

There are only nine critical vulnerabilities included in this release, and the remainder is “important.”

The most serious of the issues is CVE-2021-26424 a remote code executing vulnerability which exists in the Windows TCP/IP protocol implementation. An attacker could remotely trigger this vulnerability from a Hyper-V guest by sending a specially crafted TCP/IP packet to a host utilizing the TCP/IP protocol stack. This raises the possibility of a malicious program running in a virtual machine compromising the host environment.

Other products included in this month’s Patch Tuesday include the Windows Graphic Component, print spooler and Microsoft Office. For a full rundown of these CVEs, head to Microsoft’s security update page. Talos discovered two of the vulnerabilities patched this month: CVE-2021-26428 and CVE-2021-26430, both in Azure Sphere. We discovered these vulnerabilities as part of our ongoing participation in Microsoft’s Azure Sphere Challenge and will cover these more in-depth in a future post.

Another critical remote code execution vulnerability (CVE-2021-34535) exists in the Remote Desktop Client. This vulnerability already has a proof-of-concept available and has a severity score of 8.8 out of a possible 10. An attacker with control of a Remote Desktop Server could exploit this vulnerability to execute code on a client machine. An attacker could also potentially use a malicious program running in a guest virtual machine in Hyper-V to exploit this vulnerability to execute code.

We would also like to specifically highlight CVE-2021-26432, a critical remote code execution vulnerability in Windows Services for NFS. Microsoft’s advisory states that exploitation of this vulnerability is “more likely” and the severity score is a near-maximum 9.8.

This month’s Patch Tuesday also includes more information on the PetitPotam attack vector. This tool, which serves as a proof of concept to exploit CVE-2021-36942, has been publicly released; nevertheless, Microsoft has not yet reported the vulnerability as being exploited in the wild despite the severity score of 9.8.

This vulnerability could be used as part of an attack against domain controllers, though an attacker would first have to gain access to the internal network. Domain controllers are often a popular target for cyber attacks because they give attackers access to multiple systems once compromised.

In addition to installing the patch, Microsoft also advised users to follow other mitigation techniques they outlined in an advisory last week.

A complete list of all the vulnerabilities Microsoft disclosed this month is available on its update page.

In response to these vulnerability disclosures, Talos is releasing a new SNORTⓇ rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Firepower customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.

The rules included in this release that protect against the exploitation of many of these vulnerabilities are 57997 - 57999 and 58003.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-for-august-2021/