Microsoft Issues Security Patches for 89 Flaws — IE 0
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-24078 | Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.8 | 11% |
| — | ||
| CVE-2021-26411 | Use-After-Free Memory Corruption in Microsoft Internet Explorer Exploited in the Wild CVE-2021-26411 is a use-after-free (CWE-416) memory corruption vulnerability in Microsoft Internet Explorer's web rendering engine that can lead to remote code execution. It is triggered when a user, typically lured via a link, email, or watering-hole page, views attacker-controlled web content that corrupts memory, consistent with the CVSS profile requiring network access and user interaction. A successful attacker gains code execution in the context of the logged-on user, which in observed campaigns was chained into malware delivery (including exploit-kit payloads such as Dridex and VBA-based malware). Any Windows system that renders web content with Internet Explorer or its IE/MSHTML components (Edge is also listed among affected CPE products) is potentially affected, though specific version ranges are not provided in the source data. The flaw was exploited as a zero-day around Microsoft's March 2021 Patch Tuesday, was added to CISA KEV on 2021-11-03 with known ransomware use, and carries an 80.8% EPSS probability of exploitation within 30 days. Do: Apply Microsoft's March 2021 cumulative security updates for Internet Explorer, or any later cumulative update, across all Windows clients and servers, prioritizing user workstations per the CISA KEV required action. Review proxy and endpoint logs for visits to compromised watering-hole sites (notably Korean-language news sites) and for follow-on malware such as Dridex, and restrict or disable IE/legacy IE-mode rendering of untrusted web content where feasible. | 8.8 | 81% | KEV ransomware |
| mass≈hundreds of millions of Windows endpoints (IE/MSHTML components are present on effectively all supported Windows clients and servers) | |
| CVE-2021-26855 | Unauthenticated SSRF/RCE in Microsoft Exchange Server (ProxyLogon) CVE-2021-26855 is a server-side request forgery flaw (CWE-918) in Microsoft Exchange Server that allows an unauthenticated remote attacker to send specially crafted HTTP requests and have the Exchange server process them as itself, disclosing sensitive session information. When chained with sibling Exchange flaws (the 'ProxyLogon' chain), it yields authentication bypass and arbitrary file write, escalating to full remote code execution with SYSTEM-level privileges on the on-premises Exchange server. Any organization running an affected on-premises Exchange server reachable over HTTP/HTTPS (typically outbound webmail) is exposed; Exchange Online was not affected. Exploitation is confirmed in the wild at large scale: the flaw was mass-exploited beginning in early 2021 (notably by the HAFNIUM group), is on the CISA KEV with documented ransomware use, and has a maximum EPSS score of 100% (100th percentile), despite no public PoC listing. Do: Apply the vendor's March 2021 Exchange security updates (or later cumulative updates) immediately, per the CISA required action; until patched, limit Exchange (ECP/OWA) exposure to the internet via firewall/VPN rules. Hunt for compromise: review IIS logs for unrecognized authenticated activity against FrontEnd HttpProxy endpoints, and check for malicious files or webshells under inetpub\wwwroot\aspnet_client, given the known ransomware use. | 9.1 group max | 100% | KEV ransomware PoC ×4 |
| masshundreds of thousands of on-premises deployments; tens of thousands of internet-exposed Exchange servers | |
| CVE-2021-26867 | Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.9 | 3% |
| — | ||
| CVE-2021-26877 +1 in the same advisory: …26897 | Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.8 | 17% |
| — | ||
| CVE-2021-27076 | Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.8 | 14% |
| — | ||
| CVE-2021-27080 | Azure Sphere Unsigned Code Execution Vulnerability Azure Sphere Unsigned Code Execution Vulnerability NVD description · AI analysis pending | 9.3 | 1% | PoC |
| — |
Full article528 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMar 10, 2021
Microsoft plugged as many as 89 security flaws as part of its monthly Patch Tuesday updates released today, including fixes for an actively exploited zero-day in Internet Explorer that could permit an attacker to run arbitrary code on target machines.
Of these flaws, 14 are listed as Critical, and 75 are listed as Important in severity, out of which two of the bugs are described as publicly known, while five others have been reported as under active attack at the time of release.
Among those five security issues are a clutch of vulnerabilities known as ProxyLogon (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) that allows adversaries to break into Microsoft Exchange Servers in target environments and subsequently allow the installation of unauthorized web-based backdoors to facilitate long-term access.
But in the wake of Exchange servers coming under indiscriminate assault toward the end of February by multiple threat groups looking to exploit the vulnerabilities and plant backdoors on corporate networks, Microsoft took the unusual step of releasing out-of-band fixes a week earlier than planned.
The ramping up of mass exploitation after Microsoft released its updates on March 2 has led the company to deploy another series of security updates targeting older and unsupported cumulative updates that are vulnerable to ProxyLogon attacks.
Also included in the mix is a patch for zero-day in Internet Explorer (CVE-2021-26411) that was discovered as exploited by North Korean hackers to compromise security researchers working on vulnerability research and development earlier this year.
South Korean cybersecurity firm ENKI, which publicly disclosed the flaw early last month, claimed that North Korean nation-state hackers made an unsuccessful attempt at targeting its security researchers with malicious MHTML files that, when opened, downloaded two payloads from a remote server, one of which contained a zero-day against Internet Explorer.
Aside from these actively exploited vulnerabilities, the update also corrects a number of remote code execution (RCE) flaws in Windows DNS Server (CVE-2021-26877 and CVE-2021-26897, CVSS scores 9.8), Hyper-V server (CVE-2021-26867, CVSS score 9.9), SharePoint Server (CVE-2021-27076, CVSS score 8.8), and Azure Sphere (CVE-2021-27080, CVSS score 9.3).
CVE-2021-26877 and CVE-2021-26897 are notable for a couple of reasons. First off, the flaws are rated as "exploitation more likely" by Microsoft, and are categorized as zero-click vulnerabilities of low attack complexity that require no user interaction.
According to McAfee, the vulnerabilities stem from an out of bounds read (CVE-2021-26877) and out of bounds write (CVE-2021-26897) on the heap, respectively, during the processing of Dynamic Update packets, resulting in potential arbitrary reads and RCE.
Furthermore, this is also the second time in a row that Microsoft has addressed a critical RCE flaw in Windows DNS Server. Last month, the company rolled out a fix for CVE-2021-24078 in the same component which, if unpatched, could permit an unauthorized party to execute arbitrary code and potentially redirect legitimate traffic to malicious servers.
To install the latest security updates, Windows users can head to Start > Settings > Update & Security > Windows Update, or by selecting Check for Windows updates.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/03/microsoft-issues-security-patches-for.html