ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Update Your Windows PCs to Patch 117 New Flaws, Including 9 Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-33771
+1 in the same advisory: …31979
Privilege Escalation in Microsoft Windows Kernel Exploited in the Wild (CVE-2021-33771)

CVE-2021-33771 is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Windows kernel that allows a low-privileged user who can already execute code on a local machine to escalate to kernel-level (SYSTEM) privileges, with high impact on confidentiality, integrity and availability and no user interaction required. It is triggered locally, for example by running a malicious process or planted component on an affected system, and because it grants full SYSTEM rights it is typically chained with another flaw (such as a browser or document exploit) to escape a sandbox or complete an intrusion. Affected products span every mainstream Windows release current at disclosure: Windows 10 versions 1507, 1607, 1809, 1909, 2004, 20H2 and 21H1, Windows 8.1 and Windows RT 8.1, and Windows Server 2004, 2012 and 2016. The flaw was exploited before a patch existed; it was fixed in Microsoft's July 2021 Patch Tuesday (reported as 117 flaws including 9 zero-days, 4 actively exploited) and was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, with EPSS in the 95th percentile (~10% probability of exploitation within 30 days). Related coverage links the Windows zero-days patched in July 2021 to spyware operations by the Israeli surveillance vendor Candiru targeting journalists and activists, indicating targeted in-the-wild use rather than mass commodity exploitation.

Do: Apply Microsoft's July 2021 (or later) cumulative security updates to all affected Windows 10, 8.1, RT 8.1 and Windows Server hosts and verify the kernel update is installed, prioritizing KEV-driven remediation. Given the reported use in targeted spyware campaigns against journalists and activists, hunt on systems that ran unpatched builds for signs of compromise, such as unexpected process creation by low-privileged users, novel persistence, or unusual outbound traffic.

7.810% KEV
  • microsoft Windows 10 version 1507 builds prior to the July 2021 security update
  • microsoft Windows 10 version 1607 builds prior to the July 2021 security update
  • microsoft Windows 10 version 1809 builds prior to the July 2021 security update
  • +9 more
masshundreds of millions to 1 billion+ Windows devices and servers
CVE-2021-33779
Windows AD FS Security Feature Bypass Vulnerability

Windows AD FS Security Feature Bypass Vulnerability

NVD description · AI analysis pending
8.12%
  • microsoft windows server 2016
  • microsoft windows server 2019
CVE-2021-34492
+1 in the same advisory: …33781
Windows Certificate Spoofing Vulnerability

Windows Certificate Spoofing Vulnerability

NVD description · AI analysis pending
8.12%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2021-34448
Memory Corruption in Microsoft Windows Scripting Engine (In-the-Wild Exploitation)

CVE-2021-34448 is a memory corruption flaw (out-of-bounds write, CWE-787) in Microsoft's Windows Scripting Engine, the component that executes scripts such as JScript and VBScript on Windows. It is triggered when the engine mishandles objects in memory while processing crafted script content, typically through user interaction such as viewing a malicious web page or opening a document containing crafted script. Successful exploitation can corrupt memory in a way that lets an attacker execute code in the context of the current user, giving the attacker the victim's privileges on the machine. Essentially every Windows client and server ships the scripting engine, so the affected population is effectively all unpatched Microsoft Windows systems; exploitation is confirmed in the wild, with CISA adding the flaw to its KEV catalog on 2021-11-03 and an unusually high EPSS of 40.1% (99th percentile) indicating elevated near-term exploitation risk, though no ransomware association is confirmed and no public proof-of-concept is known. Remediation is through the vendor's Windows security updates addressing this CVE.

Do: Apply the Microsoft Windows security updates that fix CVE-2021-34448 (delivered via Windows Update in Microsoft's November 2021 release cycle) to all Windows clients and servers, prioritizing endpoints used interactively for web browsing and document handling, as CISA KEV requires prompt federal remediation. Verify each system's installed cumulative update includes the fix for this CVE before treating it as remediated. Until patched, reduce risk by limiting exposure to untrusted web content and documents (e.g., minimizing use of legacy Internet Explorer and scripting hosts) and monitor for suspicious activity involving Windows scripting components.

6.840% KEV
  • Microsoft Windows
mass≈1 billion+ Windows devices worldwide (scripting engine present on essentially every Windows installation)
CVE-2021-34458
Windows Kernel Remote Code Execution Vulnerability

Windows Kernel Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.93%
  • microsoft windows server 2016
  • microsoft windows server 2019
CVE-2021-34466
Windows Hello Security Feature Bypass Vulnerability

Windows Hello Security Feature Bypass Vulnerability

NVD description · AI analysis pending
5.7<1%
  • microsoft windows 10
CVE-2021-34473
+1 in the same advisory: …34523
SSRF (CWE-918) in Microsoft Exchange Server Enabling RCE (ProxyShell)

Microsoft Exchange Server contains a server-side request forgery (SSRF, CWE-918) in the Autodiscover service that unauthenticated remote attackers can reach over HTTP. This flaw is the first stage of the widely documented 'ProxyShell' chain, in which the SSRF is combined with privilege escalation and an arbitrary file write in the Exchange PowerShell backend to achieve unauthenticated remote code execution on the server. An attacker who successfully exploits it gains the ability to run code on the Exchange server, and ransomware operators (e.g., Cuba ransomware) leveraged this chain to deploy payloads. Organizations running on-premises Microsoft Exchange Server (2013, 2016, and 2019 per the vendor's advisories) are affected; hosted Exchange Online is a separately managed cloud service. Exploitation is confirmed in the wild: CISA added the flaw to the KEV catalog on 2021-11-03 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile).

Do: Apply Microsoft's July 2021 (or later) Exchange Server security updates, which include the ProxyShell fixes, to all on-premises servers. If patching is delayed, restrict internet access to the Autodiscover/EWS frontend endpoints and consider the URL Rewrite mitigation Microsoft published for ProxyShell. Given the KEV listing and known ransomware use, treat internet-facing, unpatched Exchange servers as potentially compromised and hunt for webshells, unusual Exchange processes, and suspicious account or mailbox activity.

9.1
group max
100% KEV ransomware PoC
  • Microsoft Exchange Server On-premises Exchange Server deployments not yet patched with Microsoft's July 2021 (or later) security updates; the source data does not enumerate specific vers
masshundreds of thousands of on-prem Exchange servers; public internet scans at the time of disclosure showed roughly 400,000+ internet-exposed Exchange instances,…
CVE-2021-34494
Windows DNS Server Remote Code Execution Vulnerability

Windows DNS Server Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.84%
  • microsoft windows server 2008
  • microsoft windows server 2012
  • microsoft windows server 2016
  • +1 more
CVE-2021-34527
PrintNightmare: Remote Code Execution in Microsoft Windows Print Spooler

CVE-2021-34527, widely known as 'PrintNightmare', is a remote code execution flaw in the Microsoft Windows Print Spooler service, which improperly performs privileged file operations such as loading printer driver DLLs. An attacker with low-level access who can reach a machine's spooler, for example a domain user able to add a printer connection via Point and Print, can induce the SYSTEM-privileged service to load an attacker-controlled DLL with no user interaction required (CVSS:3.1 vector AV:N/AC:L/PR:L/UI:N). Successful exploitation yields arbitrary code execution as SYSTEM, letting the attacker install programs, view, change or delete data, and create new accounts with full user rights, effectively achieving complete host compromise. The flaw affects all supported Windows client and server releases in the CISA data, Windows 10 from 1507 through 22H2, Windows 11, Windows RT 8.1, and Windows Server 2008, 2012 and 2016, wherever the Print Spooler service is running. Exploitation is confirmed in the wild: the bug was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, the FBI and CISA have warned of Russian actors exploiting it, and EPSS places the 30-day exploitation probability at 99.8%.

Do: Install the July 2021 security updates immediately, released July 6, 2021 with additional updates on July 7 for Windows Server 2012, Windows Server 2016 and Windows 10 version 1607, and review KB5005010 for restricting installation of new printer drivers after applying the July 6 updates. Where patching is delayed, disable the Print Spooler service on hosts that do not need printing or restrict Point and Print, and verify that NoWarningNoElevationOnInstall and UpdatePromptSettings under HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint are set to 0 or not defined (these keys do not exist by default, which is the secure state; NoWarningNoElevationOnInstall = 1 makes the system vulnerable by design). Prioritize domain controllers and servers with exposed spoolers, and hunt…

8.8100% KEV ransomware PoC ×3
  • microsoft Windows 10 1507, 1607, 1809, 20H2, 21H2, 22H2
  • microsoft Windows 11 21H2, 22H2
  • microsoft Windows RT 8.1 8.1
  • +3 more
masshundreds of millions of Windows systems (order of magnitude 10^8)
Full article689 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJul 14, 2021

Microsoft rolled out Patch Tuesday updates for the month of July with fixes for a total of 117 security vulnerabilities, including nine zero-day flaws, of which four are said to be under active attacks in the wild, potentially enabling an adversary to take control of affected systems.

Of the 117 issues, 13 are rated Critical, 103 are rated Important, and one is rated as Moderate in severity, with six of these bugs publicly known at the time of release.

The updates span across several of Microsoft's products, including Windows, Bing, Dynamics, Exchange Server, Office, Scripting Engine, Windows DNS, and Visual Studio Code. July also marks a dramatic jump in the volume of vulnerabilities, surpassing the number Microsoft collectively addressed as part of its updates in May (55) and June (50).

Chief among the security flaws actively exploited are as follows —

  • CVE-2021-34527 (CVSS score: 8.8) - Windows Print Spooler Remote Code Execution Vulnerability (publicly disclosed as "PrintNightmare")
  • CVE-2021-31979 (CVSS score: 7.8) - Windows Kernel Elevation of Privilege Vulnerability
  • CVE-2021-33771 (CVSS score: 7.8) - Windows Kernel Elevation of Privilege Vulnerability
  • CVE-2021-34448 (CVSS score: 6.8) - Scripting Engine Memory Corruption Vulnerability

Microsoft also stressed the high attack complexity of CVE-2021-34448, specifically stating that the attacks hinge on the possibility of luring an unsuspecting user into clicking on a link that leads to a malicious website hosted by the adversary and contains a specially-crafted file that's engineered to trigger the vulnerability.

The other five publicly disclosed, but not exploited, zero-day vulnerabilities are listed below —

  • CVE-2021-34473 (CVSS score: 9.1) - Microsoft Exchange Server Remote Code Execution Vulnerability
  • CVE-2021-34523 (CVSS score: 9.0) - Microsoft Exchange Server Elevation of Privilege Vulnerability
  • CVE-2021-33781 (CVSS score: 8.1) - Active Directory Security Feature Bypass Vulnerability
  • CVE-2021-33779 (CVSS score: 8.1) - Windows ADFS Security Feature Bypass Vulnerability
  • CVE-2021-34492 (CVSS score: 8.1) - Windows Certificate Spoofing Vulnerability

"This Patch Tuesday comes just days after out-of-band updates were released to address PrintNightmare — the critical flaw in the Windows Print Spooler service that was found in all versions of Windows," Bharat Jogi, senior manager of vulnerability and threat research at Qualys, told The Hacker News.

"While MSFT has released updates to fix the vulnerability, users must still ensure that necessary configurations are set up correctly. Systems with misconfigurations will continue to be at risk of exploitation, even after the latest patch has been applied. PrintNightmare was a highly serious issue that further underscores the importance of marrying detection and remediation," Jogi added.

The PrintNightmare vulnerability has also prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to release an emergency directive, urging federal departments and agencies to apply the latest security updates immediately and disable the print spooler service on servers on Microsoft Active Directory Domain Controllers.

Additionally, Microsoft also rectified a security bypass vulnerability in Windows Hello biometrics-based authentication solution (CVE-2021-34466, CVSS score: 5.7) that could permit an adversary to spoof a target's face and get around the login screen.

Other critical flaws remediated by Microsoft include remote code execution vulnerabilities affecting Windows DNS Server (CVE-2021-34494, CVSS score 8.8) and Windows Kernel (CVE-2021-34458), the latter of which is rated 9.9 on the CVSS severity scale.

"This issue allows a single root input/output virtualization (SR-IOV) device which is assigned to a guest to potentially interfere with its Peripheral Component Interface Express (PCIe) siblings which are attached to other guests or to the root," Microsoft noted in its advisory for CVE-2021-34458, adding Windows instances hosting virtual machines are vulnerable to this flaw.

To install the latest security updates, Windows users can head to Start > Settings > Update & Security > Windows Update or by selecting Check for Windows updates.

Software Patches From Other Vendors

Alongside Microsoft, patches have also been released by a number of other vendors to address several vulnerabilities, including —

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/07/update-your-windows-pcs-to-patch-117.html