Latest Microsoft Windows Updates Patch Dozens of Security Flaws
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-26419 | Scripting Engine Memory Corruption Vulnerability Scripting Engine Memory Corruption Vulnerability NVD description · AI analysis pending | 7.5 | 23% | PoC |
| — | |
| CVE-2021-28476 | Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.9 | 39% |
| — | ||
| CVE-2021-31166 | Use-After-Free RCE in Microsoft Windows HTTP Protocol Stack (http.sys) CVE-2021-31166 is a use-after-free vulnerability (CWE-416) in the Microsoft HTTP Protocol Stack, the kernel-mode HTTP service (http.sys) used by Windows components including IIS and WinRM. A remote, unauthenticated attacker can trigger the flaw by sending specially crafted network packets to a service that listens through http.sys, and reporting indicates WinRM servers are also impacted. Successful exploitation yields remote code execution in the kernel context, with full compromise potential (high confidentiality, integrity and availability impact), consistent with the wormable classification in vendor-adjacent reporting. Affected platforms are Windows 10 versions 2004 and 20H2 and Windows Server versions 2004 and 20H2, which were the current shipping Windows versions at the May 2021 Patch Tuesday release where the fix appeared. The issue is tracked in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-06) and carries a near-certain EPSS exploitation probability (~99.8%), indicating active exploitation in the wild. Do: Apply the May 2021 Patch Tuesday security updates for Windows 10 and Windows Server versions 2004 and 20H2, prioritizing internet-facing systems running IIS, WinRM, or other http.sys-based listeners. As an interim mitigation, restrict inbound access to HTTP and WinRM endpoints at the firewall. Confirm remediation by verifying the OS build includes the May 2021 cumulative update, and check the CISA KEV catalog action (apply updates per vendor instructions). | 9.8 | 100% | KEV |
| masswell over 1,000,000 vulnerable systems (tens of millions of Windows 10 2004/20H2 installs, with likely hundreds of thousands of internet-exposed servers via… | |
| CVE-2021-31207 | Security feature bypass in Microsoft Exchange Server (ProxyShell) enables webshell RCE CVE-2021-31207 is a security feature bypass in Microsoft Exchange Server, classified as an unrestricted file-write issue (CWE-434) that lets an attacker bypass intended restrictions and write files of their choosing to the server. It is the final bug in the ProxyShell chain: chained with the autodiscover SSRF and PowerShell backend elevation flaws, it allows an unauthenticated attacker to reach the Exchange PowerShell API, write arbitrary files such as an ASPX webshell, and execute code with SYSTEM privileges. A successful attacker gains full control of the on-premises Exchange server, including mailbox access, stolen credentials, and a foothold for lateral movement; the bug has been used to deploy ransomware and keyloggers. On-premises deployments of Microsoft Exchange Server (2013, 2016, and 2019 per vendor advisories) are affected, while Exchange Online/cloud mailboxes are not. Exploitation is essentially certain and ongoing: the flaw is in CISA's KEV (added 2021-11-03) with known ransomware use, public ProxyShell PoC/exploit code is available, and EPSS puts the 30-day exploitation probability at 99.8%. Do: Apply Microsoft's July 2021 security updates for Exchange Server 2013, 2016, and 2019 (or any later security/cumulative update) per vendor instructions, and restrict untrusted access to Exchange's autodiscover and PowerShell endpoints. Hunt for ASPX webshells under the Exchange FrontEnd directories and review IIS logs for autodiscover.json requests chaining PowerShell, since many servers were compromised before patching. Given known ransomware use and KEV listing, treat any server that was unpatched or internet-exposed during the exploitation window as potentially compromised. | 6.6 group max | 100% | KEV ransomware PoC |
| massHundreds of thousands of on-premises Exchange servers (public scans around the July 2021 ProxyShell disclosure showed roughly 400,000-600,000 internet-exposed… |
Full article476 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMay 12, 2021
Microsoft on Tuesday rolled out its scheduled monthly security update with patches for 55 security flaws affecting Windows, Exchange Server, Internet Explorer, Office, Hyper-V, Visual Studio, and Skype for Business.
Of these 55 bugs, four are rated as Critical, 50 are rated as Important, and one is listed as Moderate in severity. Three of the vulnerabilities are publicly known, although, unlike last month, none of them are under active exploitation at the time of release.
The most critical of the flaws addressed is CVE-2021-31166, a wormable remote code execution vulnerability in the HTTP protocol stack. The issue, which could allow an unauthenticated attacker to send a specially crafted packet to a targeted server, is rated 9.8 out of a maximum of 10 on the CVSS scale.
Another vulnerability of note is a remote code execution flaw in Hyper-V (CVE-2021-28476), which also scores the highest severity among all flaws patched this month with a CVSS rating of 9.9.
"This issue allows a guest VM to force the Hyper-V host's kernel to read from an arbitrary, potentially invalid address," Microsoft said in its advisory. "The contents of the address read would not be returned to the guest VM. In most circumstances, this would result in a denial of service of the Hyper-V host (bugcheck) due to reading an unmapped address."
"It is possible to read from a memory mapped device register corresponding to a hardware device attached to the Hyper-V host which may trigger additional, hardware device specific side effects that could compromise the Hyper-V host's security," the Windows maker noted.
In addition, the Patch Tuesday update addresses a scripting engine memory corruption flaw in Internet Explorer (CVE-2021-26419) and four weaknesses in Microsoft Exchange Server, marking the third consecutive month Microsoft has shipped fixes for the product since ProxyLogon exploits came to light in March —
- CVE-2021-31207 (CVSS score: 6.6) - Security Feature Bypass Vulnerability (publicly known)
- CVE-2021-31195 (CVSS score: 6.5) - Remote Code Execution Vulnerability
- CVE-2021-31198 (CVSS score: 7.8) - Remote Code Execution Vulnerability
- CVE-2021-31209 (CVSS score: 6.5) - Spoofing Vulnerability
While CVE-2021-31207 and CVE-2021-31209 were demonstrated at the 2021 Pwn2Own contest, Orange Tsai from DEVCORE, who disclosed the ProxyLogon Exchange Server vulnerability, is credited with reporting CVE-2021-31195.
Elsewhere, the update addresses a slew of privilege escalation bugs in Windows Container Manager Service, an information disclosure vulnerability in Windows Wireless Networking, and several remote code execution flaws in Microsoft Office, Microsoft SharePoint Server, Skype for Business, and Lync, Visual Studio, and Windows Media Foundation Core.
To install the latest security updates, Windows users can head to Start > Settings > Update & Security > Windows Update, or by selecting Check for Windows updates.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/05/latest-microsoft-windows-updates-patch.html