Microsoft patches six Windows zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-28550 | Use-After-Free RCE in Adobe Acrobat and Reader CVE-2021-28550 is a use-after-free memory corruption flaw in Adobe Acrobat DC and Acrobat Reader DC that an unauthenticated attacker can trigger by getting a victim to open a malicious PDF file. Successful exploitation allows arbitrary code execution in the context of the current user, giving the attacker the privileges of that user on the affected machine. Anyone running Acrobat or Acrobat Reader DC at or below versions 2021.001.20150, 2020.001.30020, or 2017.011.30194 is affected. The flaw was exploited as a zero-day in targeted attacks — Microsoft reported it being chained with Windows zero-days by an Austrian company's operators — and it is listed in CISA's Known Exploited Vulnerabilities catalog as of November 3, 2021. CISA's required action is to apply vendor updates, and defenders should treat exploited, user-targeted PDF attacks as the primary risk. Do: Upgrade Acrobat and Acrobat Reader DC to versions later than 2021.001.20150, 2020.001.30020, and 2017.011.30194 on the respective tracks, per Adobe's May 2021 update and the CISA KEV required action. Until patched, avoid opening PDFs from untrusted sources and consider email-gateway filtering or sandboxing of PDF attachments. Check endpoint inventory for the affected version ranges and prioritize systems of users who handle unsolicited documents. | 8.8 | 52% | KEV |
| masshundreds of millions of installations (Acrobat Reader is the world's most widely deployed PDF viewer) | |
| CVE-2021-31199 +1 in the same advisory: …31201 | Elevation of Privilege in Microsoft Enhanced Cryptographic Provider (Windows) CVE-2021-31199 is an elevation-of-privilege vulnerability in the Microsoft Enhanced Cryptographic Provider, a core Windows component that provides cryptographic services to applications. It carries a CVSS 3.1 score of 5.2 (AV:L/AC:L/PR:L/UI:N/S:C), meaning it is triggered by an attacker who already runs low-privileged code locally on a vulnerable Windows system, with no user interaction required, and lets the attacker break out of the intended security scope to gain elevated privileges. The gain is higher privileges on the compromised host, typically used as a stepping stone in a broader intrusion or malware delivery chain. Exposure is broad: any unpatched Windows 7, 8.1, RT 8.1, Windows 10 (versions 1507 through 21H1), Windows Server 2008, or Windows Server 2004 system is affected, since the provider ships with Windows itself. Exploitation is confirmed in the wild: it was one of the actively exploited Windows zero-days fixed in Microsoft's mid-2021 Patch Tuesday release (part of the six/seven-zero-day coverage), Microsoft attributed targeted attacks to the Austrian firm DSIRF using its Subzero surveillance malware, and the flaw was added to CISA's KEV on 2021-11-03; EPSS estimates a 3.0% chance of exploitation in the next 30 days (86th percentile) and no public PoC is known. Do: Apply Microsoft's security updates (the monthly Patch Tuesday cumulative updates covering this CVE) per vendor instructions for every in-scope Windows version — the flaw is in CISA KEV, so patching is mandatory for federal agencies and there is no documented workaround. Verify hosts have received the updated cumulative update, prioritizing multi-user endpoints, RDP/terminal servers, and workstations where untrusted code runs; if patching is delayed, hunt for signs of targeted intrusion consistent with DSIRF/Subzero activity. | 5.2 | 3% | KEV |
| mass≈1 billion+ Windows devices (Windows 10 alone had over 1 billion active devices, and the affected set also includes Windows 7/8.1/RT 8.1 and Windows Server… | |
| CVE-2021-33742 | Out-of-Bounds Write RCE in Microsoft Windows MSHTML Engine (CVE-2021-33742) A remote code execution vulnerability exists in the Microsoft Windows MSHTML Platform — the Internet Explorer/Trident rendering engine that Windows components and applications invoke to display web content — caused by an out-of-bounds write (CWE-787). An attacker triggers it by persuading a user to open attacker-controlled content, such as a crafted document or web page that causes MSHTML to render a remote URL; no privileges are required, but user interaction is needed and the attack is rated high complexity. Successful exploitation runs attacker code in the context of the logged-in user, potentially allowing installation of programs, viewing/changing/deleting data, or creating new accounts with the victim's rights. The affected range spans Windows 7, 8.1, RT 8.1, Windows 10 versions 1507 through 21H1, and Windows Server 2008 and 2012 — essentially the entire supported Windows installed base at the time of disclosure. Exploitation is confirmed in the wild: Microsoft disclosed the flaw as used in limited targeted attacks, CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware use unknown), and EPSS assigns a 59.4% 30-day exploitation probability (99th percentile). Do: Apply Microsoft's security update for CVE-2021-33742, delivered via the July 2021 cumulative Windows updates (and later), to all affected Windows 7/8.1/RT 8.1/10 clients and Windows Server 2008/2012 hosts, prioritizing internet-exposed systems and per CISA's required action. Because exploitation requires user interaction, treat unsolicited documents and links with caution until systems are patched. No public proof-of-concept is known, but the KEV listing confirms real-world targeted exploitation, so assume active scanning/attacks and verify patch status across the estate. | 7.5 group max | 59% | KEV |
| masson the order of 1 billion+ Windows installations | |
| CVE-2021-31962 | Kerberos AppContainer Security Feature Bypass Vulnerability Kerberos AppContainer Security Feature Bypass Vulnerability NVD description · AI analysis pending | 9.4 | 4% |
| — |
Full article638 words · extracted from therecord.media · click to collapse
Microsoft has released today its monthly batch of security updates, known in the industry as Patch Tuesday. This month's security patches fix 50 vulnerabilities, including six actively exploited Windows zero-days, representing the largest batch of actively exploited zero-days patched in one go in the company's recent history. Details about how the six zero-days have been kept under wraps, as is usually the case with these types of disclosures, primarily to give defenders more time to apply patches before other threat actors can learn how to exploit the bugs. However, some small details have leaked, from Google and Kaspersky, two of the companies that reported the ongoing attacks to Microsoft in the first place. The most interesting of the six zero-days is CVE-2021-33742, a remote code execution vulnerability in the MSHTML component that is part of the Internet Explorer browser. In a tweet on Tuesday, Shane Huntley, head of the Google Threat Analysis Group, said his team discovered this vulnerability being abused in the wild and all signs pointed that the exploit appears to have been developed by a professional commercial exploit broker. While Huntley didn't share technical details about the zero-day, which he promised his team will share in 30 days, the Google TAG head said the exploit appears to have been used by a nation-state for a small number of attacks against targets in Eastern Europe and the Middle East. More details will be on CVE-2021-33742 will come from the team, but for context this seem to be a commercial exploit company providing capability for limited nation state Eastern Europe / Middle East targeting. But while Google was able to link the MSHTML zero-day attacks to an exploit broker and a nation-state entity, Kaspersky is still looking for details about two zero-days its researchers caught last month. Tracked as CVE-2021-31955 and CVE-2021-31956, the Russian security firm said the two Windows bugs were part of a complex exploit chain that also involved a web delivery via the Chrome browser. "While we were not able to retrieve the exploit used for remote code execution (RCE) in the Chrome web browser, we were able to find and analyze an elevation of privilege (EoP) exploit that was used to escape the sandbox and obtain system privileges," researchers said in a report published today shortly after Microsoft released its Patch Tuesday updates. Both Windows zero-days, which exploited two distinct vulnerabilities in the Microsoft Windows OS kernel, were particularly interesting because they were fine-tuned to work against the latest and most prominent builds of Windows 10 (17763 – RS5, 18362 – 19H1, 18363 – 19H2, 19041 – 20H1, 19042 – 20H2), suggesting that the threat actor was interested in targeting modern and up-to-date devices. Additionally, Microsoft also patched two zero-days in CVE-2021-31199 and CVE-2021-31201 that were related to an Adobe Reader zero-day (CVE-2021-28550) that Adobe patched last month in May. Both zero-days impact one of Microsoft's cryptographic libraries and even impact old versions of Windows, such as 7 and Server 2012. Unfortunately, neither the Adobe nor the Microsoft patch notes reveal any information about the attacks.CVE-2021-33742: A commercial exploit
Two zero-days targeted recent versions of Windows 10
Two 0-days linked to last month's Adobe Reader zero-day
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/microsoft-patches-six-windows-zero-days-including-a-commercial-exploit