ZeroHour
The Recordpublished ()ingested 1

Microsoft patches Office zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-36965
+1 in the same advisory: …26435
Windows WLAN AutoConfig Service Remote Code Execution Vulnerability

Windows WLAN AutoConfig Service Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.8
group max
5%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2021-36968
Windows DNS Elevation of Privilege Vulnerability

Windows DNS Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.8<1%
  • microsoft windows 7
  • microsoft windows server 2008
CVE-2021-40444
Remote Code Execution via MSHTML Rendering Engine in Microsoft Windows/Office (CVE-2021-40444)

CVE-2021-40444 is a remote code execution vulnerability in the Microsoft MSHTML browser rendering engine, which Microsoft Office documents can load on Windows systems. It is triggered when a user is convinced to open a specially crafted Office document containing a malicious ActiveX control hosted by the MSHTML engine (tracked as a path-traversal-class issue, CWE-22). A successful attacker gains the ability to run arbitrary code in the context of the logged-on user, with greater impact when that user has administrative rights. Any Windows system that can open Office documents is exposed, spanning Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 21H1) and Windows Server 2004/2008. Exploitation is confirmed in the wild: Microsoft observed targeted attacks at disclosure, the flaw is in CISA's KEV with known ransomware use, and Microsoft released security updates on September 14, 2021.

Do: Apply Microsoft's security updates released September 14, 2021 for your Windows version immediately; this is a CISA KEV item with known ransomware use, so patching is treated as mandatory. As interim protection, keep Microsoft Defender Antivirus/Defender for Endpoint signatures current (enterprise detection build 1.349.22.0 or newer, with alerts appearing as 'Suspicious Cpl File Execution') and avoid opening untrusted Office documents, since exploitation requires user interaction with a crafted file.

8.897% KEV ransomware PoC ×2
  • microsoft MSHTML as shipped in the affected Windows releases
  • microsoft Windows 10 1507, 1607, 1809, 1909, 2004, 20H2, 21H1
  • microsoft Windows 7 all versions covered by Microsoft's September 2021 security updates
  • +4 more
masshundreds of millions of Windows PCs and servers (nearly all Windows desktop/laptop installs on affected versions at disclosure)
Full article487 words · extracted from therecord.media · click to collapse

Microsoft has released patches today for a zero-day vulnerability in one of the Windows components that was abused in the wild for attacks using weaponized Office documents.

First disclosed last week, when Microsoft warned of the attacks and published basic mitigations, the OS maker has released official fixes as today, part of its monthly Patch Tuesday security updates.

Tracked as CVE-2021-40444, patches have been made available for Windows versions as far back as Windows 7 and Windows Server 2008.

The bug resides in the Microsoft MHTML component, also known as Trident, the old Internet Explorer browser engine. Microsoft said it discovered instances where a threat actor had created malicious Office files that used the MHTML component to load web-based content inside the documents, such as a malicious ActiveX control, which exploited CVE-2021-40444 to run code on the underlying Windows OS.

A successful attack allowed threat actors to gain control over a user's OS, Microsoft said last week.

While no technical details were revealed last week, security researchers and malware developers quickly figured out what the issue was and published proof-of-concept code to exploit the bug was eventually on both GitHub and underground hacking forums, and the code has already been weaponized and integrated as part of attacks spotted this week.

A campaign with it today targeting Russian telcos...

— alex lanstein (@alex_lanstein) September 13, 2021

Fortunately, today's Office zero-day patch also comes just in time, as several security researchers discovered last week ways to bypass Microsoft's temporary mitigation solutions [12], meaning that Windows users were fully exposed to these attacks without any kind of protection.

However, if the patches hold up remains to be seen. Several security researchers have publicly stated that the bug is buried deep enough in core Office behavior that attackers could easily find new ways to abuse this issue, creating another scenario similar to Microsoft's PrintNightmare never-ending patching conundrum.

The September 2021 Patch Tuesday also fixes 85 other bugs

But besides fixes for CVE-2021, Microsoft has also released other security updates today, with patches for 85 other bugs, 48 of which are Edge/Chromium-related issues.

Of these, the most important appears to be CVE-2021-36968, an elevation of privilege in the Windows DNS service, for which details have been publicly shared on the internet.

"According to Microsoft, it is not being exploited in the wild," said Allan Liska, threat intelligence analyst at Recorded Future. "It is labelled Important by Microsoft and, interestingly, only impacts Windows 7 and Windows Server 2008."

Other issues to keep an eye on, and reasons to apply today's patches as soon as possible, are CVE-2021-36965 and CVE-2021-26435, Liska said.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/microsoft-patches-office-zero-day-in-todays-patch-tuesday