Microsoft Patch Tuesday for Nov. 2021 — Snort rules and prominent vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-26443 +1 in the same advisory: …38666 | Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.0 group max | 2% |
| — | ||
| CVE-2021-42292 | Security Feature Bypass in Microsoft Excel Enables Arbitrary Code Execution Microsoft Excel, a component of Microsoft Office, contains a security feature bypass (CWE-357, insufficient verification of data authenticity) that would allow a local user to achieve arbitrary code execution. The flaw is triggered when Excel fails to properly verify data authenticity, allowing a file handled by Excel to bypass one of its security features rather than being processed safely. Successful exploitation lets an attacker run arbitrary code in the context of the local user, typically requiring the user to open Excel content on their machine. Anyone running the affected Microsoft Office/Excel software is exposed; the source data does not specify affected version ranges or fixed builds. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-17, confirming in-the-wild exploitation, and it carries a high 43% EPSS probability of exploitation within 30 days (99th percentile), though no public proof-of-concept is known and ransomware use is unknown. Do: Apply Microsoft's security updates for Office/Excel addressing CVE-2021-42292 per vendor instructions (the November 2021 Patch Tuesday release; the source data does not list specific fixed versions, so check Microsoft's advisory for affected builds). Federal agencies must patch by the CISA KEV required deadline. Until patched, exercise caution opening Excel files from untrusted or internet-sourced locations, since exploitation requires local user interaction. | 7.8 | 43% | KEV |
| masshundreds of millions of users (Excel is deployed on the vast majority of Windows endpoints worldwide) | |
| CVE-2021-42298 | Microsoft Defender Remote Code Execution Vulnerability Microsoft Defender Remote Code Execution Vulnerability NVD description · AI analysis pending | 7.8 | 6% |
| — |
Full article560 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, November 9, 2021 15:26
By Jon Munshaw and Tiago Pereira.
Microsoft released its monthly security update Tuesday, disclosing 56 vulnerabilities in the company’s various software, hardware and firmware offerings, including one that’s actively being exploited in the wild.
November’s security update features six critical vulnerabilities, up from last month’s two, which was far lower than average for Microsoft. The other 50 vulnerabilities fixed today are considered “important.”
CVE-2021-42292 is one of those vulnerabilities considered “important” and not critical, though it is the only one included in this security update that Microsoft reports has been spotted being exploited in the wild. An attacker could exploit this vulnerability in Microsoft Excel to bypass certain security settings on targeted machines.
In a time when email attachments are the major vector of system compromise, this vulnerability can be used to increase the efficiency of these attacks by avoiding a security prompt and consequently reducing the social engineering necessary to infect the victim. One critical vulnerability we would like to highlight is CVE-2021-38666, a remote code execution vulnerability in Remote Desktop Client. An attacker with control of a Remote Desktop Server could exploit this vulnerability to trigger remote code execution on the client machine if they trick a victim into connecting to the attacker-controlled server running a vulnerable version of the Remote Desktop Client. Because of this, there are limited cases where the vulnerability could be exploited. However, this issue should not be ignored, as there are specific circumstances in which this vulnerability could be used to obtain further privileges or for lateral movement.
Another code execution vulnerability (CVE-2021-42298) exists in Windows Defender, the free anti-virus service pre-installed on all Windows desktop devices. A specially crafted file could trigger execution when it’s scanned by Windows Defender or opened by the user. This is a very efficient way for an attacker to potentially infect a remote system where a malicious file is delivered, such as through email or instant messaging apps.
It’s also worth noting CVE-2021-26443, a code execution vulnerability in Microsoft Virtual Machine Bus that has a CVSS severity score of 9 out of 10. This vulnerability could allow command execution by a guest VM on a host VM, resulting in an escalation of privileges. This vulnerability is critical in certain environments that make use of untrusted Microsoft Virtual Machines.
Talos also discovered multiple vulnerabilities in Azure Sphere that Microsoft patched over the past few months, including four disclosed today. Some of them did not receive official patches nor assigned CVEs. For more on this, read our full blog post here.
A complete list of all the vulnerabilities Microsoft disclosed this month is available on its update page.
In response to these vulnerability disclosures, Talos is releasing a new SNORTⓇ rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Cisco Secure Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.
The rules included in this release that protect against the exploitation of many of these vulnerabilities are 58519, 58520, 58539 - 58541. There is also Snort 3 rule 300054.
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-for-nov-2021/