ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Microsoft Expands Coverage for Exchange Server Bugs

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-0792
An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevati

An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0715, CVE-2020-0745.

NVD description · AI analysis pending
8.81%
  • microsoft windows 10
  • microsoft windows server 2016
CVE-2021-26411
Use-After-Free Memory Corruption in Microsoft Internet Explorer Exploited in the Wild

CVE-2021-26411 is a use-after-free (CWE-416) memory corruption vulnerability in Microsoft Internet Explorer's web rendering engine that can lead to remote code execution. It is triggered when a user, typically lured via a link, email, or watering-hole page, views attacker-controlled web content that corrupts memory, consistent with the CVSS profile requiring network access and user interaction. A successful attacker gains code execution in the context of the logged-on user, which in observed campaigns was chained into malware delivery (including exploit-kit payloads such as Dridex and VBA-based malware). Any Windows system that renders web content with Internet Explorer or its IE/MSHTML components (Edge is also listed among affected CPE products) is potentially affected, though specific version ranges are not provided in the source data. The flaw was exploited as a zero-day around Microsoft's March 2021 Patch Tuesday, was added to CISA KEV on 2021-11-03 with known ransomware use, and carries an 80.8% EPSS probability of exploitation within 30 days.

Do: Apply Microsoft's March 2021 cumulative security updates for Internet Explorer, or any later cumulative update, across all Windows clients and servers, prioritizing user workstations per the CISA KEV required action. Review proxy and endpoint logs for visits to compromised watering-hole sites (notably Korean-language news sites) and for follow-on malware such as Dridex, and restrict or disable IE/legacy IE-mode rendering of untrusted web content where feasible.

8.881% KEV ransomware
  • microsoft internet_explorer
  • microsoft edge
mass≈hundreds of millions of Windows endpoints (IE/MSHTML components are present on effectively all supported Windows clients and servers)
CVE-2021-26877
+3 in the same advisory: …26894 …26895 …26893
Windows DNS Server Remote Code Execution Vulnerability

Windows DNS Server Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.817%
  • microsoft windows server 2008
  • microsoft windows server 2012
  • microsoft windows server 2016
  • +1 more
CVE-2021-27077
Windows Win32k Elevation of Privilege Vulnerability

Windows Win32k Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.81%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
Full article324 words · extracted from infosecurity-magazine.com · click to collapse

Microsoft released fixes for over 80 CVEs in yesterday’s Patch Tuesday update round, including a zero-day bug and several publicly disclosed vulnerabilities.

In a week dominated by the exploitation on a massive scale of four zero-day Exchange Server flaws patched out-of-band by Microsoft last week, there’s yet more to do for sysadmins.

The first is yet another zero-day, this time in Internet Explorer.

CVE-2021-26411 is a memory corruption vulnerability that could allow an attacker to target users with specially crafted content,” explained Ivanti senior director of product management, Chris Goettl.

“An attacker could utilize specially crafted websites or websites that accept user-provided content or advertisements to host content designed to exploit this vulnerability.”

Experts also urged IT teams to patch a publicly disclosed vulnerability (CVE-2021-27077) in Windows Win32k that could allow an attacker to elevate privileges on an affected system. It was first reported by Trend Micro’s Zero Day Initiative back in January.

“This vulnerability is not believed to be exploited in the wild, however, the length of time between initial disclosure and a patch being released should be cause for concern as it may have given malicious threat actors the opportunity to figure out the vulnerability and exploit it,” warned Recorded Future senior security architect, Allan Liska.

“A similar vulnerability, also discovered by the Zero Day Initiative, reported last year, CVE-2020-0792, was not widely exploited.”

Of the six Microsoft DNS bugs patched this month, Liska argued that CVE-2021-26877, CVE-2021-26893, CVE-2021-26894 and CVE-2021-26895 should be prioritized as they are remote code execution flaws which impact Windows Server 2008-2016.

Elsewhere, Microsoft expanded the coverage of patches issued for those widely exploited Exchange Server bugs to include out-of-support cumulative updates (CUs) – including Exchange Server 2019 CU 6, CU 5 and CU 4 and Exchange Server 2016 CU 16, CU 15, and CU14.

“This is an indication of the severity and reach of the attacks targeting the Exchange Server on-prem products,” said Goettl.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-expands-coverage/