Microsoft Issues Patches for Actively Exploited Excel, Exchange Server 0
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-26443 | Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.0 group max | 2% |
| — | ||
| CVE-2021-3711 | In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then allocate a sufficiently sized buffer and call EVP_PKEY_decrypt() again, but this time passing a non-NULL value for the "out" parameter. A bug in the implementation of the SM2 decryption code means that the calculation of the buffer size required to hold the plaintext returned by the first call to EVP_PKEY_decrypt() can be smaller than the actual size required by the second call. This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small. A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen data to overflow the buffer by up to a maximum of 62 bytes altering the contents of other data held after the buffer, possibly changing application behaviour or causing the application to crash. The location of the buffer is application dependent but is typically heap allocated. Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k). NVD description · AI analysis pending | 9.8 | 88% |
| — | ||
| CVE-2021-42292 | Security Feature Bypass in Microsoft Excel Enables Arbitrary Code Execution Microsoft Excel, a component of Microsoft Office, contains a security feature bypass (CWE-357, insufficient verification of data authenticity) that would allow a local user to achieve arbitrary code execution. The flaw is triggered when Excel fails to properly verify data authenticity, allowing a file handled by Excel to bypass one of its security features rather than being processed safely. Successful exploitation lets an attacker run arbitrary code in the context of the local user, typically requiring the user to open Excel content on their machine. Anyone running the affected Microsoft Office/Excel software is exposed; the source data does not specify affected version ranges or fixed builds. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-17, confirming in-the-wild exploitation, and it carries a high 43% EPSS probability of exploitation within 30 days (99th percentile), though no public proof-of-concept is known and ransomware use is unknown. Do: Apply Microsoft's security updates for Office/Excel addressing CVE-2021-42292 per vendor instructions (the November 2021 Patch Tuesday release; the source data does not list specific fixed versions, so check Microsoft's advisory for affected builds). Federal agencies must patch by the CISA KEV required deadline. Until patched, exercise caution opening Excel files from untrusted or internet-sourced locations, since exploitation requires local user interaction. | 7.8 | 43% | KEV |
| masshundreds of millions of users (Excel is deployed on the vast majority of Windows endpoints worldwide) | |
| CVE-2021-42298 | Microsoft Defender Remote Code Execution Vulnerability Microsoft Defender Remote Code Execution Vulnerability NVD description · AI analysis pending | 7.8 | 6% |
| — | ||
| CVE-2021-42316 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2021-42321 | Authenticated RCE via Insecure Deserialization in Microsoft Exchange Server CVE-2021-42321 is an insecure deserialization remote code execution flaw in on-premises Microsoft Exchange Server, tied to insufficient validation by Exchange's ChainedSerializationBinder. Per the CVSS vector, it is triggered over the network by an authenticated user with low privileges and no user interaction, by submitting crafted serialized data that Exchange fails to safely deserialize. A successful attacker gains arbitrary code execution on the Exchange server with high impact to confidentiality, integrity, and availability, giving a foothold in the mail environment. Organizations running affected on-premises Exchange deployments are in scope. The flaw was actively exploited before patches shipped in November 2021, has public PoC exploits, was added to CISA's KEV on 2021-11-17 with known ransomware use, and carries an EPSS of 91.7% (99.9+ percentile). Do: Apply the November 2021 Microsoft Exchange Server security updates per vendor instructions to affected on-premises Exchange 2016/2019 deployments. Given confirmed in-the-wild exploitation and known ransomware use, check Exchange servers for signs of compromise, verify backups, and review accounts holding privileged Exchange roles, since exploitation requires authenticated access — enforce MFA and audit impersonation/admin role assignments while patching. | 8.8 | 92% | KEV ransomware PoC ×2 |
| masshundreds of thousands of internet-facing on-premises Exchange servers (on the order of 10^5 endpoints, supporting millions of mailbox users) | |
| CVE-2021-42322 | Visual Studio Code Elevation of Privilege Vulnerability Visual Studio Code Elevation of Privilege Vulnerability NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2021-43209 +1 in the same advisory: …43208 | 3D Viewer Remote Code Execution Vulnerability 3D Viewer Remote Code Execution Vulnerability NVD description · AI analysis pending | 7.8 | 7% |
| — |
Full article545 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananNov 10, 2021
Microsoft has released security updates as part of its monthly Patch Tuesday release cycle to address 55 vulnerabilities across Windows, Azure, Visual Studio, Windows Hyper-V, and Office, including fixes for two actively exploited zero-day flaws in Excel and Exchange Server that could be abused to take control of an affected system.
Of the 55 glitches, six are rated Critical and 49 are rated as Important in severity, with four others listed as publicly known at the time of release.
The most critical of the flaws are CVE-2021-42321 (CVSS score: 8.8) and CVE-2021-42292 (CVSS score: 7.8), each concerning a post-authentication remote code execution flaw in Microsoft Exchange Server and a security bypass vulnerability impacting Microsoft Excel versions 2013-2021 respectively.
The Exchange Server issue is also one of the bugs that was demonstrated at the Tianfu Cup held in China last month. However, the Redmond-based tech giant did not provide any details on how the two aforementioned vulnerabilities were used in real-world attacks.
"Earlier this year, Microsoft alerted that APT Group HAFNIUM was exploiting four zero-day vulnerabilities in the Microsoft Exchange server," said Bharat Jogi, director of vulnerability and threat research at Qualys.
"This evolved into exploits of Exchange server vulnerabilities by DearCry Ransomware — including attacks on infectious disease researchers, law firms, universities, defense contractors, policy think tanks and NGOs. Instances such as these further underscore that Microsoft Exchange servers are high-value targets for hackers looking to penetrate critical networks," Jogi added.
Also addressed are four publicly disclosed, but not exploited, vulnerabilities —
- CVE-2021-43208 (CVSS score: 7.8) - 3D Viewer Remote Code Execution Vulnerability
- CVE-2021-43209 (CVSS score: 7.8) - 3D Viewer Remote Code Execution Vulnerability
- CVE-2021-38631 (CVSS score: 4.4) - Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
- CVE-2021-41371 (CVSS score: 4.4) - Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Microsoft's November patch also comes with a resolution for CVE-2021-3711, a critical buffer overflow flaw in OpenSSL's SM2 decryption function that came to light in late August 2021 and could be abused by adversaries to run arbitrary code and cause a denial-of-service (DoS) condition.
Other important remediations include fixes for multiple remote code execution flaws in Chakra Scripting Engine (CVE-2021-42279), Microsoft Defender (CVE-2021-42298), Microsoft Virtual Machine Bus (CVE-2021-26443), Remote Desktop Client (CVE-2021-38666), and on-premises versions of Microsoft Dynamics 365 (CVE-2021-42316).
Lastly, the update is rounded by patches for a number of privilege escalation vulnerabilities affecting NTFS (CVE-2021-41367, CVE-2021-41370, CVE-2021-42283), Windows Kernel (CVE-2021-42285), Visual Studio Code (CVE-2021-42322), Windows Desktop Bridge (CVE-2021-36957), and Windows Fast FAT File System Driver (CVE-2021-41377)
To install the latest security updates, Windows users can head to Start > Settings > Update & Security > Windows Update or by selecting Check for Windows updates.
Software Patches From Other Vendors
In addition to Microsoft, security updates have also been released by a number of other vendors to rectify several vulnerabilities, including —
- Adobe
- Android
- Cisco
- Citrix
- Intel
- Linux distributions Oracle Linux, Red Hat, and SUSE
- Samba
- SAP
- Schneider Electric, and
- Siemens
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/11/microsoft-issues-patches-for-actively.html