ZeroHour
Cisco Talospublished ()ingested

Microsoft Patch Tuesday for July 2021 — Snort rules and prominent vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-33771
+1 in the same advisory: …31979
Privilege Escalation in Microsoft Windows Kernel Exploited in the Wild (CVE-2021-33771)

CVE-2021-33771 is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Windows kernel that allows a low-privileged user who can already execute code on a local machine to escalate to kernel-level (SYSTEM) privileges, with high impact on confidentiality, integrity and availability and no user interaction required. It is triggered locally, for example by running a malicious process or planted component on an affected system, and because it grants full SYSTEM rights it is typically chained with another flaw (such as a browser or document exploit) to escape a sandbox or complete an intrusion. Affected products span every mainstream Windows release current at disclosure: Windows 10 versions 1507, 1607, 1809, 1909, 2004, 20H2 and 21H1, Windows 8.1 and Windows RT 8.1, and Windows Server 2004, 2012 and 2016. The flaw was exploited before a patch existed; it was fixed in Microsoft's July 2021 Patch Tuesday (reported as 117 flaws including 9 zero-days, 4 actively exploited) and was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, with EPSS in the 95th percentile (~10% probability of exploitation within 30 days). Related coverage links the Windows zero-days patched in July 2021 to spyware operations by the Israeli surveillance vendor Candiru targeting journalists and activists, indicating targeted in-the-wild use rather than mass commodity exploitation.

Do: Apply Microsoft's July 2021 (or later) cumulative security updates to all affected Windows 10, 8.1, RT 8.1 and Windows Server hosts and verify the kernel update is installed, prioritizing KEV-driven remediation. Given the reported use in targeted spyware campaigns against journalists and activists, hunt on systems that ran unpatched builds for signs of compromise, such as unexpected process creation by low-privileged users, novel persistence, or unusual outbound traffic.

7.810% KEV
  • microsoft Windows 10 version 1507 builds prior to the July 2021 security update
  • microsoft Windows 10 version 1607 builds prior to the July 2021 security update
  • microsoft Windows 10 version 1809 builds prior to the July 2021 security update
  • +9 more
masshundreds of millions to 1 billion+ Windows devices and servers
CVE-2021-33780
Windows DNS Server Remote Code Execution Vulnerability

Windows DNS Server Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.83%
  • microsoft windows server 2008
  • microsoft windows server 2012
  • microsoft windows server 2016
  • +1 more
CVE-2021-34448
Memory Corruption in Microsoft Windows Scripting Engine (In-the-Wild Exploitation)

CVE-2021-34448 is a memory corruption flaw (out-of-bounds write, CWE-787) in Microsoft's Windows Scripting Engine, the component that executes scripts such as JScript and VBScript on Windows. It is triggered when the engine mishandles objects in memory while processing crafted script content, typically through user interaction such as viewing a malicious web page or opening a document containing crafted script. Successful exploitation can corrupt memory in a way that lets an attacker execute code in the context of the current user, giving the attacker the victim's privileges on the machine. Essentially every Windows client and server ships the scripting engine, so the affected population is effectively all unpatched Microsoft Windows systems; exploitation is confirmed in the wild, with CISA adding the flaw to its KEV catalog on 2021-11-03 and an unusually high EPSS of 40.1% (99th percentile) indicating elevated near-term exploitation risk, though no ransomware association is confirmed and no public proof-of-concept is known. Remediation is through the vendor's Windows security updates addressing this CVE.

Do: Apply the Microsoft Windows security updates that fix CVE-2021-34448 (delivered via Windows Update in Microsoft's November 2021 release cycle) to all Windows clients and servers, prioritizing endpoints used interactively for web browsing and document handling, as CISA KEV requires prompt federal remediation. Verify each system's installed cumulative update includes the fix for this CVE before treating it as remediated. Until patched, reduce risk by limiting exposure to untrusted web content and documents (e.g., minimizing use of legacy Internet Explorer and scripting hosts) and monitor for suspicious activity involving Windows scripting components.

6.840% KEV
  • Microsoft Windows
mass≈1 billion+ Windows devices worldwide (scripting engine present on essentially every Windows installation)
CVE-2021-34449
Win32k Elevation of Privilege Vulnerability

Win32k Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.03%
  • microsoft windows 10
  • microsoft windows server 2016
  • microsoft windows server 2019
CVE-2021-34464
Microsoft Defender Remote Code Execution Vulnerability

Microsoft Defender Remote Code Execution Vulnerability

NVD description · AI analysis pending
7.83%
  • microsoft malware protection engine
CVE-2021-34467
Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft SharePoint Server Remote Code Execution Vulnerability

NVD description · AI analysis pending
7.17%
  • microsoft sharepoint foundation
  • microsoft sharepoint server
CVE-2021-34520
+1 in the same advisory: …34468
Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft SharePoint Server Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.1
group max
4%
  • microsoft sharepoint foundation
  • microsoft sharepoint server
CVE-2021-34473
SSRF (CWE-918) in Microsoft Exchange Server Enabling RCE (ProxyShell)

Microsoft Exchange Server contains a server-side request forgery (SSRF, CWE-918) in the Autodiscover service that unauthenticated remote attackers can reach over HTTP. This flaw is the first stage of the widely documented 'ProxyShell' chain, in which the SSRF is combined with privilege escalation and an arbitrary file write in the Exchange PowerShell backend to achieve unauthenticated remote code execution on the server. An attacker who successfully exploits it gains the ability to run code on the Exchange server, and ransomware operators (e.g., Cuba ransomware) leveraged this chain to deploy payloads. Organizations running on-premises Microsoft Exchange Server (2013, 2016, and 2019 per the vendor's advisories) are affected; hosted Exchange Online is a separately managed cloud service. Exploitation is confirmed in the wild: CISA added the flaw to the KEV catalog on 2021-11-03 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile).

Do: Apply Microsoft's July 2021 (or later) Exchange Server security updates, which include the ProxyShell fixes, to all on-premises servers. If patching is delayed, restrict internet access to the Autodiscover/EWS frontend endpoints and consider the URL Rewrite mitigation Microsoft published for ProxyShell. Given the KEV listing and known ransomware use, treat internet-facing, unpatched Exchange servers as potentially compromised and hunt for webshells, unusual Exchange processes, and suspicious account or mailbox activity.

9.1100% KEV ransomware PoC
  • Microsoft Exchange Server On-premises Exchange Server deployments not yet patched with Microsoft's July 2021 (or later) security updates; the source data does not enumerate specific vers
masshundreds of thousands of on-prem Exchange servers; public internet scans at the time of disclosure showed roughly 400,000+ internet-exposed Exchange instances,…
Full article569 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, July 13, 2021 14:09

By Jon Munshaw, with contributions from Jaeson Schultz.

Microsoft released its monthly security update Tuesday, disclosing 117 vulnerabilities across its suite of products, by far the most in a month this year. Today’s Patch Tuesday includes three vulnerabilities that Microsoft states are being exploited in the wild, which we will cover in more detail.

There are 13 critical vulnerabilities patched in this month, and there is one low- and moderate-severity vulnerability each. The remainder are considered “important.”

Most notably, Microsoft has released an update to patch the “PrintNightmare” vulnerability in its print spooler function that could allow an attacker to execute remote code. This vulnerability was first disclosed in April, though security researchers later discovered it could be exploited in a more serious way than initially thought. Microsoft attempted to fix the vulnerability with an out-of-band release earlier this month, though it’s believed the vulnerability could still be exploited.

For more on this, check out Talos’ blog with our associated protections and analysis.

Other products included in this month’s Patch Tuesday include Hyper-V, Microsoft Defender and Windows DNS. For a full rundown of these CVEs, head to Microsoft’s security update page.

Besides the print spooler vulnerability, there is one other issue attackers have exploited in the wild, according to Microsoft. CVE-2021-34448 is a memory corruption vulnerability in the Scripting Engine that is triggered when the user opens a specially crafted file, either attached to an email or a compromised website.

There is another critical vulnerability, CVE-2021-34473, in Microsoft Exchange Server. This vulnerability was already patched in Microsoft’s April security update but was mistakenly not disclosed. Users who already installed the April 2021 update are already protected from this vulnerability, though it is worth noting that this issue was part of a series of zero-days in Exchange Server used in a wide-ranging APT attack.

Microsoft Defender, the company’s built-in anti-virus software to most of its machines, also contains a critical vulnerability: CVE-2021-34464. This issue could allow an attacker to execute remote code on the victim machine. However, users do not need to take any actions to resolve this issue, as the update will automatically install. The company has listed steps in its advisory users can take to ensure the update is properly installed.

We would also like to highlight three vulnerabilities in SharePoint Server that could allow an attacker to execute remote code on the victim machine. CVE-2021-34520, CVE-2021-34467 and CVE-2021-34468 all are “important.” However, Microsoft reports that exploitation is “more likely” in these vulnerabilities.

There are several other important vulnerabilities that are also classified as being “more likely” to be exploited:

A complete list of all the vulnerabilities Microsoft disclosed this month is available on its update page.

In response to these vulnerability disclosures, Talos is releasing a new SNORTⓇ rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Firepower customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.

The rules included in this release that protect against the exploitation of many of these vulnerabilities are 57890, 57891, 57894 - 57897 and 57906 - 57910.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-for-july-2021/