ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-28550
Use-After-Free RCE in Adobe Acrobat and Reader

CVE-2021-28550 is a use-after-free memory corruption flaw in Adobe Acrobat DC and Acrobat Reader DC that an unauthenticated attacker can trigger by getting a victim to open a malicious PDF file. Successful exploitation allows arbitrary code execution in the context of the current user, giving the attacker the privileges of that user on the affected machine. Anyone running Acrobat or Acrobat Reader DC at or below versions 2021.001.20150, 2020.001.30020, or 2017.011.30194 is affected. The flaw was exploited as a zero-day in targeted attacks — Microsoft reported it being chained with Windows zero-days by an Austrian company's operators — and it is listed in CISA's Known Exploited Vulnerabilities catalog as of November 3, 2021. CISA's required action is to apply vendor updates, and defenders should treat exploited, user-targeted PDF attacks as the primary risk.

Do: Upgrade Acrobat and Acrobat Reader DC to versions later than 2021.001.20150, 2020.001.30020, and 2017.011.30194 on the respective tracks, per Adobe's May 2021 update and the CISA KEV required action. Until patched, avoid opening PDFs from untrusted sources and consider email-gateway filtering or sandboxing of PDF attachments. Check endpoint inventory for the affected version ranges and prioritize systems of users who handle unsolicited documents.

8.852% KEV
  • adobe Acrobat Reader DC 2021.001.20150 and earlier; 2020.001.30020 and earlier; 2017.011.30194 and earlier
  • adobe Acrobat DC 2021.001.20150 and earlier; 2020.001.30020 and earlier; 2017.011.30194 and earlier
  • adobe Acrobat affected per CISA (see DC ranges above)
  • +1 more
masshundreds of millions of installations (Acrobat Reader is the world's most widely deployed PDF viewer)
CVE-2021-31199
+1 in the same advisory: …31201
Elevation of Privilege in Microsoft Enhanced Cryptographic Provider (Windows)

CVE-2021-31199 is an elevation-of-privilege vulnerability in the Microsoft Enhanced Cryptographic Provider, a core Windows component that provides cryptographic services to applications. It carries a CVSS 3.1 score of 5.2 (AV:L/AC:L/PR:L/UI:N/S:C), meaning it is triggered by an attacker who already runs low-privileged code locally on a vulnerable Windows system, with no user interaction required, and lets the attacker break out of the intended security scope to gain elevated privileges. The gain is higher privileges on the compromised host, typically used as a stepping stone in a broader intrusion or malware delivery chain. Exposure is broad: any unpatched Windows 7, 8.1, RT 8.1, Windows 10 (versions 1507 through 21H1), Windows Server 2008, or Windows Server 2004 system is affected, since the provider ships with Windows itself. Exploitation is confirmed in the wild: it was one of the actively exploited Windows zero-days fixed in Microsoft's mid-2021 Patch Tuesday release (part of the six/seven-zero-day coverage), Microsoft attributed targeted attacks to the Austrian firm DSIRF using its Subzero surveillance malware, and the flaw was added to CISA's KEV on 2021-11-03; EPSS estimates a 3.0% chance of exploitation in the next 30 days (86th percentile) and no public PoC is known.

Do: Apply Microsoft's security updates (the monthly Patch Tuesday cumulative updates covering this CVE) per vendor instructions for every in-scope Windows version — the flaw is in CISA KEV, so patching is mandatory for federal agencies and there is no documented workaround. Verify hosts have received the updated cumulative update, prioritizing multi-user endpoints, RDP/terminal servers, and workstations where untrusted code runs; if patching is delayed, hunt for signs of targeted intrusion consistent with DSIRF/Subzero activity.

5.23% KEV
  • microsoft Windows 10 1507, 1607, 1809, 1909, 2004, 20H2, 21H1
  • microsoft Windows 7 all supported builds at time of disclosure
  • microsoft Windows 8.1 all supported builds
  • +3 more
mass≈1 billion+ Windows devices (Windows 10 alone had over 1 billion active devices, and the affected set also includes Windows 7/8.1/RT 8.1 and Windows Server…
CVE-2021-33739
+3 in the same advisory: …33742 …31956 …31955
Privilege Escalation in Microsoft Windows Desktop Window Manager (DWM) Core Library

CVE-2021-33739 is an elevation-of-privilege vulnerability in the Microsoft Desktop Window Manager (DWM) Core Library, the component that composites the Windows graphical desktop. A local attacker who can already execute code on a vulnerable machine — for example via a malicious application, an Office payload, or a chained remote code execution bug — can exploit the flaw in DWM to gain elevated privileges on the system. Successful exploitation yields high-impact results (CVSS 8.4, high for confidentiality, integrity and availability), and the bug is typically used to break out of a low-privileged context or complete a full compromise chain. Affected systems are Windows 10 versions 1909, 2004, 20H2 and 21H1, and Windows Server versions 2004 and 20H2, prior to the June 2021 security updates. The flaw was one of six zero-days Microsoft confirmed as actively exploited in the June 2021 Patch Tuesday release; it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 and carries a 6.6% EPSS (93rd percentile), although no public PoC is known and ransomware use is undetermined.

Do: Apply the June 2021 (or later) Windows cumulative updates on Windows 10 1909/2004/20H2/21H1 and Windows Server 2004/20H2, consistent with CISA's required action to apply vendor updates. Because this is a local privilege escalation, prioritize hosts where untrusted or multi-user code runs (VDI, RDS, kiosks, jump servers) and environments with KEV-mandated remediation deadlines. Verify patch status against the June 2021 release, since the bug was confirmed exploited in the wild.

8.4
group max
7% KEV
  • microsoft Windows 10 1909 (pre-June 2021 Patch Tuesday updates)
  • microsoft Windows 10 2004 (pre-June 2021 Patch Tuesday updates)
  • microsoft Windows 10 20H2 (pre-June 2021 Patch Tuesday updates)
  • +3 more
masshundreds of millions of endpoints (Windows 10's installed base exceeds 1 billion devices; builds 1909 through 21H1 were the dominant Windows 10 releases in…
CVE-2021-31963
Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft SharePoint Server Remote Code Execution Vulnerability

NVD description · AI analysis pending
7.12%
  • microsoft sharepoint foundation
  • microsoft sharepoint server
CVE-2021-31968
Windows Remote Desktop Services Denial of Service Vulnerability

Windows Remote Desktop Services Denial of Service Vulnerability

NVD description · AI analysis pending
7.53%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
Full article327 words · extracted from infosecurity-magazine.com · click to collapse

Microsoft announced patches for a half-century of CVEs this month, including seven zero-day vulnerabilities, six of which are being actively exploited in the wild.

The six vulnerabilities in question start with CVE-2021-31955, an information disclosure bug in Windows kernel, and remote code execution flaw CVE-2021-33742.

The rest are elevation of privilege bugs in Windows NTFS (CVE-2021-31956), the Microsoft Enhanced Cryptographic Provider (CVE-2021-31199 and CVE-2021-31201) and the Microsoft DWM Core Library (CVE-2021-33739).

In addition, CVE-2021-31968 is a denial of service vulnerability in Windows Remote Desktop Services, which has been publicly disclosed but not yet seen in attacks.

Chris Goettl, Ivanti senior director of product management and security, said that CVE-2021-31199 and CVE-2021-28550 are related to a previously exploited Adobe flaw, CVE-2021-28550, released in the Adobe Security Bulletin ID APSB21-29.

“Customers running affected versions of Microsoft Windows should install the June security updates to be fully protected from these three vulnerabilities,” he added. “This vulnerability affects Windows 7, Server 2008 and later Windows OS versions and is rated as ‘important’ with a CVSSv3 base score of 5.2, which could be missed in some organizations’ prioritization.”

In fact, many of the zero-days published on Tuesday don’t at first glance appear to be particularly risky for organizations due to their low CVSS scores.

“This brings a very important prioritization challenge to the forefront this month. Vendor severity ratings and scoring systems like CVSS may not reflect the real-world risk in many cases,” warned Goettl.

“Adopting a risk-based vulnerability management approach and using additional risk indicators and telemetry on real-world attack trends is vital to stay ahead of threats like modern ransomware.”

Elsewhere this month, Recorded Future senior solution architect, Allan Liska, urged sysadmins to focus on CVE-2021-31963, a critical remote code execution vulnerability in Microsoft SharePoint Server.

Although not previously disclosed or exploited in the wild, similar bugs have been used to deliver payloads, including ransomware in the past, he warned.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-fixes-seven-zerodays/