ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Microsoft patches actively exploited Exchange, Excel zero-days (CVE-2021-42321, CVE-2021-42292)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-26443
+1 in the same advisory: …38666
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability

Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.0
group max
2%
  • microsoft windows 10
  • microsoft windows 11
  • microsoft windows server 2016
  • +1 more
CVE-2021-42292
Security Feature Bypass in Microsoft Excel Enables Arbitrary Code Execution

Microsoft Excel, a component of Microsoft Office, contains a security feature bypass (CWE-357, insufficient verification of data authenticity) that would allow a local user to achieve arbitrary code execution. The flaw is triggered when Excel fails to properly verify data authenticity, allowing a file handled by Excel to bypass one of its security features rather than being processed safely. Successful exploitation lets an attacker run arbitrary code in the context of the local user, typically requiring the user to open Excel content on their machine. Anyone running the affected Microsoft Office/Excel software is exposed; the source data does not specify affected version ranges or fixed builds. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-17, confirming in-the-wild exploitation, and it carries a high 43% EPSS probability of exploitation within 30 days (99th percentile), though no public proof-of-concept is known and ransomware use is unknown.

Do: Apply Microsoft's security updates for Office/Excel addressing CVE-2021-42292 per vendor instructions (the November 2021 Patch Tuesday release; the source data does not list specific fixed versions, so check Microsoft's advisory for affected builds). Federal agencies must patch by the CISA KEV required deadline. Until patched, exercise caution opening Excel files from untrusted or internet-sourced locations, since exploitation requires local user interaction.

7.843% KEV
  • Microsoft Office (Excel)
masshundreds of millions of users (Excel is deployed on the vast majority of Windows endpoints worldwide)
CVE-2021-42298
Microsoft Defender Remote Code Execution Vulnerability

Microsoft Defender Remote Code Execution Vulnerability

NVD description · AI analysis pending
7.86%
  • microsoft malware protection engine
CVE-2021-42321
Authenticated RCE via Insecure Deserialization in Microsoft Exchange Server

CVE-2021-42321 is an insecure deserialization remote code execution flaw in on-premises Microsoft Exchange Server, tied to insufficient validation by Exchange's ChainedSerializationBinder. Per the CVSS vector, it is triggered over the network by an authenticated user with low privileges and no user interaction, by submitting crafted serialized data that Exchange fails to safely deserialize. A successful attacker gains arbitrary code execution on the Exchange server with high impact to confidentiality, integrity, and availability, giving a foothold in the mail environment. Organizations running affected on-premises Exchange deployments are in scope. The flaw was actively exploited before patches shipped in November 2021, has public PoC exploits, was added to CISA's KEV on 2021-11-17 with known ransomware use, and carries an EPSS of 91.7% (99.9+ percentile).

Do: Apply the November 2021 Microsoft Exchange Server security updates per vendor instructions to affected on-premises Exchange 2016/2019 deployments. Given confirmed in-the-wild exploitation and known ransomware use, check Exchange servers for signs of compromise, verify backups, and review accounts holding privileged Exchange roles, since exploitation requires authenticated access — enforce MFA and audit impersonation/admin role assignments while patching.

8.892% KEV ransomware PoC ×2
  • microsoft exchange server
masshundreds of thousands of internet-facing on-premises Exchange servers (on the order of 10^5 endpoints, supporting millions of mailbox users)
Full article399 words · extracted from helpnetsecurity.com · click to collapse

It’s a light November 2021 Patch Tuesday from Microsoft: 55 fixed CVEs, of which two are zero-days under active exploitation: CVE-2021-42321, a Microsoft Exchange RCE, and CVE-2021-42292, a Microsoft Excel security feature bypass bug.

CVE-2021-42321 CVE-2021-42292

Vulnerabilities of note

CVE-2021-42321, the remote code execution vulnerability in Microsoft Exchange Server 2016 and 2019, is due to issues with the validation of command-let (cmdlet) arguments.

“In order to exploit this flaw, an attacker would need to be authenticated, which limits some of the impact. Microsoft says they are aware of ‘limited targeted attacks’ using this vulnerability in the wild,” says Satnam Narang, staff research engineer at Tenable.

In a blog post published by the Exchange Team, the company recommended that the provided updates for Microsoft Exchange be installed immediately. They delineated two possible update paths, and shared a PowerShell query that security teams can use to check to see if an exploit was attempted on their servers.

The in-the-wild exploitation of CVE-2021-42292, the Microsoft Excel security feature bypass zero-day, was apparently discovered by Microsoft’s Security Threat Intelligence Center (MSTIC).

“This patch fixes a bug that could allow code execution when opening a specially crafted file with an affected version of Excel. This is likely due to loading code that should be behind a prompt, but for whatever reason, that prompt does not appear, thus bypassing that security feature,” noted Dustin Childs, with Trend Micro’s Zero Day Initiative.

“It’s unclear if it’s a malicious macro or some other form of code loading within a spreadsheet, but I would be reluctant to open any unexpected attachments for a while. This is especially true for users of Office for Mac because there currently is no patch available for Mac users.”

Other vulnerabilities worth singling out include:

  • CVE-2021-38666, a Remote Desktop Client RCE vulnerability, that could be exploited by attackers if they are able to trick users into connecting to a malicious RCP server
  • CVE-2021-42298, a Microsoft Defender RCE hole that will be plugged automatically on internet-connected systems when they receive the malware definition updates and the update for the Microsoft Malware Protection Engine
  • CVE-2021-26443 a RCE affecting Microsoft Virtual Machine Bus (VMBus) that may allow a guest-to-host escape. “A user on a guest VM can send a specially crafted communication on the VMBus channel to the host OS that could result in arbitrary code execution on the underlying host,” Childs explained.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/11/09/cve-2021-42321-cve-2021-42292/