ZeroHour
Security Affairspublished ()ingested @securityaffairs1

Microsoft June 2021 Patch Tuesday addresses 6 0days actively exploited

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-31199
+1 in the same advisory: …31201
Elevation of Privilege in Microsoft Enhanced Cryptographic Provider (Windows)

CVE-2021-31199 is an elevation-of-privilege vulnerability in the Microsoft Enhanced Cryptographic Provider, a core Windows component that provides cryptographic services to applications. It carries a CVSS 3.1 score of 5.2 (AV:L/AC:L/PR:L/UI:N/S:C), meaning it is triggered by an attacker who already runs low-privileged code locally on a vulnerable Windows system, with no user interaction required, and lets the attacker break out of the intended security scope to gain elevated privileges. The gain is higher privileges on the compromised host, typically used as a stepping stone in a broader intrusion or malware delivery chain. Exposure is broad: any unpatched Windows 7, 8.1, RT 8.1, Windows 10 (versions 1507 through 21H1), Windows Server 2008, or Windows Server 2004 system is affected, since the provider ships with Windows itself. Exploitation is confirmed in the wild: it was one of the actively exploited Windows zero-days fixed in Microsoft's mid-2021 Patch Tuesday release (part of the six/seven-zero-day coverage), Microsoft attributed targeted attacks to the Austrian firm DSIRF using its Subzero surveillance malware, and the flaw was added to CISA's KEV on 2021-11-03; EPSS estimates a 3.0% chance of exploitation in the next 30 days (86th percentile) and no public PoC is known.

Do: Apply Microsoft's security updates (the monthly Patch Tuesday cumulative updates covering this CVE) per vendor instructions for every in-scope Windows version — the flaw is in CISA KEV, so patching is mandatory for federal agencies and there is no documented workaround. Verify hosts have received the updated cumulative update, prioritizing multi-user endpoints, RDP/terminal servers, and workstations where untrusted code runs; if patching is delayed, hunt for signs of targeted intrusion consistent with DSIRF/Subzero activity.

5.23% KEV
  • microsoft Windows 10 1507, 1607, 1809, 1909, 2004, 20H2, 21H1
  • microsoft Windows 7 all supported builds at time of disclosure
  • microsoft Windows 8.1 all supported builds
  • +3 more
mass≈1 billion+ Windows devices (Windows 10 alone had over 1 billion active devices, and the affected set also includes Windows 7/8.1/RT 8.1 and Windows Server…
CVE-2021-33739
+3 in the same advisory: …33742 …31956 …31955
Privilege Escalation in Microsoft Windows Desktop Window Manager (DWM) Core Library

CVE-2021-33739 is an elevation-of-privilege vulnerability in the Microsoft Desktop Window Manager (DWM) Core Library, the component that composites the Windows graphical desktop. A local attacker who can already execute code on a vulnerable machine — for example via a malicious application, an Office payload, or a chained remote code execution bug — can exploit the flaw in DWM to gain elevated privileges on the system. Successful exploitation yields high-impact results (CVSS 8.4, high for confidentiality, integrity and availability), and the bug is typically used to break out of a low-privileged context or complete a full compromise chain. Affected systems are Windows 10 versions 1909, 2004, 20H2 and 21H1, and Windows Server versions 2004 and 20H2, prior to the June 2021 security updates. The flaw was one of six zero-days Microsoft confirmed as actively exploited in the June 2021 Patch Tuesday release; it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 and carries a 6.6% EPSS (93rd percentile), although no public PoC is known and ransomware use is undetermined.

Do: Apply the June 2021 (or later) Windows cumulative updates on Windows 10 1909/2004/20H2/21H1 and Windows Server 2004/20H2, consistent with CISA's required action to apply vendor updates. Because this is a local privilege escalation, prioritize hosts where untrusted or multi-user code runs (VDI, RDS, kiosks, jump servers) and environments with KEV-mandated remediation deadlines. Verify patch status against the June 2021 release, since the bug was confirmed exploited in the wild.

8.4
group max
7% KEV
  • microsoft Windows 10 1909 (pre-June 2021 Patch Tuesday updates)
  • microsoft Windows 10 2004 (pre-June 2021 Patch Tuesday updates)
  • microsoft Windows 10 20H2 (pre-June 2021 Patch Tuesday updates)
  • +3 more
masshundreds of millions of endpoints (Windows 10's installed base exceeds 1 billion devices; builds 1909 through 21H1 were the dominant Windows 10 releases in…
CVE-2021-31968
Windows Remote Desktop Services Denial of Service Vulnerability

Windows Remote Desktop Services Denial of Service Vulnerability

NVD description · AI analysis pending
7.53%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
Full article345 words · extracted from securityaffairs.com · click to collapse

Microsoft’s June 2021 Patch Tuesday addressed 50 vulnerabilities, including six zero-day issues that are being actively exploited in the wild.

Microsoft’s June 2021 Patch Tuesday addresses 50 vulnerabilities in Microsoft Windows, .NET Core and Visual Studio, Microsoft Office, Microsoft Edge (Chromium-based and EdgeHTML), SharePoint Server, Hyper-V, Visual Studio Code – Kubernetes Tools, Windows HTML Platform, and Windows Remote Desktop. Five vulnerabilities fixed by Microsoft’s June 2021 Patch Tuesday are rated Critical and 45 are rated Important in severity. Microsoft experts confirmed that six of these flaws are currently under active attack and three are publicly known at the time of release.

Eight of the flaws fixed by Microsoft were reported by the Zero Day Initiative (ZDI), other issues were reported by Google’s Threat Analysis Group, Google Project Zero, Check Point Research, FireEye, Kaspersky, and Nixu Cybersecurity. 

The six zero-day vulnerabilities actively exploited in the wild are:

  • CVE-2021-33742: Windows MSHTML Platform Remote Code Execution Vulnerability, CVSS 7.5
  • CVE-2021-33739: Microsoft DWM Core Library Elevation of Privilege Vulnerability, CVSS 8.4
  • CVE-2021-31199: Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability, CVSS 5.2
  • CVE-2021-31201: Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability, CVSS 5.2
  • CVE-2021-31955: Windows Kernel Information Disclosure Vulnerability, CVSS 5.5
  • CVE-2021-31956: Windows NTFS Elevation of Privilege Vulnerability, CVSS 7.8

Microsoft also addressed another zero-day flaw, tracked as CVE-2021-31968, which is a DoS issue that affects Windows Remote Desktop Services.

Kaspersky discovered two of the zero-day vulnerabilities, so we will likely see a report coming soon explaining how they were used.

“Looking at the remaining Critical-rated bugs, the update for Defender stands out even though you likely won’t need to take any action. Microsoft regularly updates the Malware Protection Engine, so if your system is connected to the Internet, it should have already received an update.” reads the post published by the ZeroDayInitiative.

The list of issues addressed by the IT giant is available here.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft’s June 2021 Patch Tuesday)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/118750/security/microsoft-june-2021-patch-tuesday.html