ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

May 2021 Patch Tuesday: Adobe fixes exploited Reader 0-day, Microsoft patches 55 holes

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-24587
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renewed.

NVD description · AI analysis pending
2.63% PoC
  • ieee ieee 802.11
  • ieee mac80211
  • ieee debian linux
  • +1 more
CVE-2021-21084
AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by a stored Cross-Site Scripting

AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

NVD description · AI analysis pending
6.12%
  • adobe experience manager
  • adobe experience manager cloud service
CVE-2021-26419
Scripting Engine Memory Corruption Vulnerability

Scripting Engine Memory Corruption Vulnerability

NVD description · AI analysis pending
7.523% PoC
  • microsoft internet explorer
CVE-2021-27068
Visual Studio Remote Code Execution Vulnerability

Visual Studio Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.854%
  • microsoft visual studio 2019
CVE-2021-28476
Windows Hyper-V Remote Code Execution Vulnerability

Windows Hyper-V Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.939%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2021-28550
Use-After-Free RCE in Adobe Acrobat and Reader

CVE-2021-28550 is a use-after-free memory corruption flaw in Adobe Acrobat DC and Acrobat Reader DC that an unauthenticated attacker can trigger by getting a victim to open a malicious PDF file. Successful exploitation allows arbitrary code execution in the context of the current user, giving the attacker the privileges of that user on the affected machine. Anyone running Acrobat or Acrobat Reader DC at or below versions 2021.001.20150, 2020.001.30020, or 2017.011.30194 is affected. The flaw was exploited as a zero-day in targeted attacks — Microsoft reported it being chained with Windows zero-days by an Austrian company's operators — and it is listed in CISA's Known Exploited Vulnerabilities catalog as of November 3, 2021. CISA's required action is to apply vendor updates, and defenders should treat exploited, user-targeted PDF attacks as the primary risk.

Do: Upgrade Acrobat and Acrobat Reader DC to versions later than 2021.001.20150, 2020.001.30020, and 2017.011.30194 on the respective tracks, per Adobe's May 2021 update and the CISA KEV required action. Until patched, avoid opening PDFs from untrusted sources and consider email-gateway filtering or sandboxing of PDF attachments. Check endpoint inventory for the affected version ranges and prioritize systems of users who handle unsolicited documents.

8.852% KEV
  • adobe Acrobat Reader DC 2021.001.20150 and earlier; 2020.001.30020 and earlier; 2017.011.30194 and earlier
  • adobe Acrobat DC 2021.001.20150 and earlier; 2020.001.30020 and earlier; 2017.011.30194 and earlier
  • adobe Acrobat affected per CISA (see DC ranges above)
  • +1 more
masshundreds of millions of installations (Acrobat Reader is the world's most widely deployed PDF viewer)
CVE-2021-31166
Use-After-Free RCE in Microsoft Windows HTTP Protocol Stack (http.sys)

CVE-2021-31166 is a use-after-free vulnerability (CWE-416) in the Microsoft HTTP Protocol Stack, the kernel-mode HTTP service (http.sys) used by Windows components including IIS and WinRM. A remote, unauthenticated attacker can trigger the flaw by sending specially crafted network packets to a service that listens through http.sys, and reporting indicates WinRM servers are also impacted. Successful exploitation yields remote code execution in the kernel context, with full compromise potential (high confidentiality, integrity and availability impact), consistent with the wormable classification in vendor-adjacent reporting. Affected platforms are Windows 10 versions 2004 and 20H2 and Windows Server versions 2004 and 20H2, which were the current shipping Windows versions at the May 2021 Patch Tuesday release where the fix appeared. The issue is tracked in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-06) and carries a near-certain EPSS exploitation probability (~99.8%), indicating active exploitation in the wild.

Do: Apply the May 2021 Patch Tuesday security updates for Windows 10 and Windows Server versions 2004 and 20H2, prioritizing internet-facing systems running IIS, WinRM, or other http.sys-based listeners. As an interim mitigation, restrict inbound access to HTTP and WinRM endpoints at the firewall. Confirm remediation by verifying the OS build includes the May 2021 cumulative update, and check the CISA KEV catalog action (apply updates per vendor instructions).

9.8100% KEV
  • Microsoft Windows 10 version 2004
  • Microsoft Windows 10 version 20H2
  • Microsoft Windows Server version 2004
  • +2 more
masswell over 1,000,000 vulnerable systems (tens of millions of Windows 10 2004/20H2 installs, with likely hundreds of thousands of internet-exposed servers via…
Full article631 words · extracted from helpnetsecurity.com · click to collapse

On this May 2021 Patch Tuesday:

  • Adobe has fixed a Reader flaw exploited in attacks in the wild, as well as delivered security updates for eleven other products, including Magento, Adobe InDesign, Adobe After Effects, Adobe Creative Cloud Desktop Application, and others
  • Microsoft has plugged 55 security holes, none actively exploited
  • SAP has released 14 new and updated security patches

May 2021 Patch Tuesday

Adobe updates

Adobe has released security updates for 12 of its products, fixing a total of 44 CVE-numbered flaws.

The updates that should be prioritized are those for Adobe Acrobat and Reader for Windows and macOS, because they fix a number of critical and important vulnerabilities in a widely used product that has often been targeted by attackers. Another good reason is that one of these – CVE-2021-28550 – “has been exploited in the wild in limited attacks targeting Adobe Reader users on Windows.”

According to Adobe, the Experience Manager should be next, as the product has historically been at elevated risk. The update solves two flaws, one of which – CVE-2021-21084 – could allow attackers to execute arbitrary JavaScript in the user’s browser.

The rest of the updates can be implemented in due time, as most of those products are very specific and are rarely (if ever) targeted. Though flaws in Magento are often exploited, the ones fixed in this update are not critical.

Microsoft updates

Microsoft delivered a lighter than usual load of updates on this May 2021 Patch Tuesday, though it covers a wide variety of products.

55 vulnerabilities in all have been fixed, 4 of which are critical, 3 previously publicly known, and (luckily) none are currently exploited by attackers.

Dustin Childs of Trend Micro’s Zero Day Initiative advises administrators to prioritize the patches for:

The first one because it can be exploited by sending a specially crafted packet to an affected server (including Windows 10, when configured as a web server) and because it’s wormable. The second one because it’s been deemed highly critical (though more likely to be exploited for DoS than RCE).

The third one because an attacker would need low privileges and no user interaction for exploitation, and the complexity of the attack has been categorized as “low”. The fourth one because it could allow an attacker to disclose the contents of encrypted wireless packets on an affected system.

This last one is also part of a batch of security vulnerabilities that affect Wi-Fi devices, which have been unearthed and reported by Mathy Vanhoef, a postdoctoral researcher at New York University Abu Dhabi

Finally, administrators should consider a quick implementation of updates for Microsoft Exchange Server and Microsoft SharePoint Server, as they are often targeted by attackers.

Kevin Breen, Director of Cyber Threat Research at Immersive Labs, also advises quick patching of CVE-2021-26419, a Scripting Engine memory corruption vulnerability affecting Internet Explorer 11.

“To trigger the vulnerability, a user would have to visit a site that is controlled by the attacker, although Microsoft also recognizes that it could be triggered by embedding ActiveX controls in Office Documents,” he noted.

“If you are an organization that has to provide IE11 to support legacy applications, consider enforcing a policy on the users that restricts the domains that can be accessed by IE11 to only those legacy applications. All other web browsing should be performed with a supported browser.”

SAP updates

SAP has released 14 new and updated security patches.

The most crucial updates in this batch are for SAP Business Client (fixing a flaw in the browser control Google Chromium delivered with it), SAP Commerce (fixing a RCE), and SAP Business Warehouse and SAP BW/4HANA.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/05/12/may-2021-patch-tuesday/