July 2021 Patch Tuesday: Microsoft fixes 4 actively exploited bugs
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-0144 | Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege via local a Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege via local access. NVD description · AI analysis pending | 6.7 | <1% |
| — | ||
| CVE-2021-21994 +1 in the same advisory: …21995 | SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request. NVD description · AI analysis pending | 9.8 group max | 1% |
| — | ||
| CVE-2021-33771 +1 in the same advisory: …31979 | Privilege Escalation in Microsoft Windows Kernel Exploited in the Wild (CVE-2021-33771) CVE-2021-33771 is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Windows kernel that allows a low-privileged user who can already execute code on a local machine to escalate to kernel-level (SYSTEM) privileges, with high impact on confidentiality, integrity and availability and no user interaction required. It is triggered locally, for example by running a malicious process or planted component on an affected system, and because it grants full SYSTEM rights it is typically chained with another flaw (such as a browser or document exploit) to escape a sandbox or complete an intrusion. Affected products span every mainstream Windows release current at disclosure: Windows 10 versions 1507, 1607, 1809, 1909, 2004, 20H2 and 21H1, Windows 8.1 and Windows RT 8.1, and Windows Server 2004, 2012 and 2016. The flaw was exploited before a patch existed; it was fixed in Microsoft's July 2021 Patch Tuesday (reported as 117 flaws including 9 zero-days, 4 actively exploited) and was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, with EPSS in the 95th percentile (~10% probability of exploitation within 30 days). Related coverage links the Windows zero-days patched in July 2021 to spyware operations by the Israeli surveillance vendor Candiru targeting journalists and activists, indicating targeted in-the-wild use rather than mass commodity exploitation. Do: Apply Microsoft's July 2021 (or later) cumulative security updates to all affected Windows 10, 8.1, RT 8.1 and Windows Server hosts and verify the kernel update is installed, prioritizing KEV-driven remediation. Given the reported use in targeted spyware campaigns against journalists and activists, hunt on systems that ran unpatched builds for signs of compromise, such as unexpected process creation by low-privileged users, novel persistence, or unusual outbound traffic. | 7.8 | 10% | KEV |
| masshundreds of millions to 1 billion+ Windows devices and servers | |
| CVE-2021-34448 | Memory Corruption in Microsoft Windows Scripting Engine (In-the-Wild Exploitation) CVE-2021-34448 is a memory corruption flaw (out-of-bounds write, CWE-787) in Microsoft's Windows Scripting Engine, the component that executes scripts such as JScript and VBScript on Windows. It is triggered when the engine mishandles objects in memory while processing crafted script content, typically through user interaction such as viewing a malicious web page or opening a document containing crafted script. Successful exploitation can corrupt memory in a way that lets an attacker execute code in the context of the current user, giving the attacker the victim's privileges on the machine. Essentially every Windows client and server ships the scripting engine, so the affected population is effectively all unpatched Microsoft Windows systems; exploitation is confirmed in the wild, with CISA adding the flaw to its KEV catalog on 2021-11-03 and an unusually high EPSS of 40.1% (99th percentile) indicating elevated near-term exploitation risk, though no ransomware association is confirmed and no public proof-of-concept is known. Remediation is through the vendor's Windows security updates addressing this CVE. Do: Apply the Microsoft Windows security updates that fix CVE-2021-34448 (delivered via Windows Update in Microsoft's November 2021 release cycle) to all Windows clients and servers, prioritizing endpoints used interactively for web browsing and document handling, as CISA KEV requires prompt federal remediation. Verify each system's installed cumulative update includes the fix for this CVE before treating it as remediated. Until patched, reduce risk by limiting exposure to untrusted web content and documents (e.g., minimizing use of legacy Internet Explorer and scripting hosts) and monitor for suspicious activity involving Windows scripting components. | 6.8 | 40% | KEV |
| mass≈1 billion+ Windows devices worldwide (scripting engine present on essentially every Windows installation) | |
| CVE-2021-34458 | Windows Kernel Remote Code Execution Vulnerability Windows Kernel Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.9 | 3% |
| — | ||
| CVE-2021-34466 | Windows Hello Security Feature Bypass Vulnerability Windows Hello Security Feature Bypass Vulnerability NVD description · AI analysis pending | 5.7 | <1% |
| — | ||
| CVE-2021-34527 | PrintNightmare: Remote Code Execution in Microsoft Windows Print Spooler CVE-2021-34527, widely known as 'PrintNightmare', is a remote code execution flaw in the Microsoft Windows Print Spooler service, which improperly performs privileged file operations such as loading printer driver DLLs. An attacker with low-level access who can reach a machine's spooler, for example a domain user able to add a printer connection via Point and Print, can induce the SYSTEM-privileged service to load an attacker-controlled DLL with no user interaction required (CVSS:3.1 vector AV:N/AC:L/PR:L/UI:N). Successful exploitation yields arbitrary code execution as SYSTEM, letting the attacker install programs, view, change or delete data, and create new accounts with full user rights, effectively achieving complete host compromise. The flaw affects all supported Windows client and server releases in the CISA data, Windows 10 from 1507 through 22H2, Windows 11, Windows RT 8.1, and Windows Server 2008, 2012 and 2016, wherever the Print Spooler service is running. Exploitation is confirmed in the wild: the bug was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, the FBI and CISA have warned of Russian actors exploiting it, and EPSS places the 30-day exploitation probability at 99.8%. Do: Install the July 2021 security updates immediately, released July 6, 2021 with additional updates on July 7 for Windows Server 2012, Windows Server 2016 and Windows 10 version 1607, and review KB5005010 for restricting installation of new printer drivers after applying the July 6 updates. Where patching is delayed, disable the Print Spooler service on hosts that do not need printing or restrict Point and Print, and verify that NoWarningNoElevationOnInstall and UpdatePromptSettings under HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint are set to 0 or not defined (these keys do not exist by default, which is the secure state; NoWarningNoElevationOnInstall = 1 makes the system vulnerable by design). Prioritize domain controllers and servers with exposed spoolers, and hunt… | 8.8 | 100% | KEV ransomware PoC ×3 |
| masshundreds of millions of Windows systems (order of magnitude 10^8) |
Full article1,024 words · extracted from helpnetsecurity.com · click to collapse
On this July 2021 Patch Tuesday:
- Microsoft has fixed 117 CVEs, 4 of which are actively exploited
- Adobe has delivered security updates for Acrobat and Reader, Bridge, Framemaker, Illustrator, and Dimension
- VMware has fixed two vulnerabilities in VMware ESXi and VMware Cloud Foundation
- SAP has released 12 security notes and updated 3
- Intel has fixed an EOP bug affecting some of its Xeon and Core X-series processors
- Mozilla has upgraded Firefox and Firefox ESR, fixed security flaws and improved security features

Microsoft
Microsoft has released patches for 117 CVEs, 13 of which are considered to be critical. 6 of the total are publicly known, and 4 are actively exploited (including CVE-2021-34527, aka PrintNightmare).
“There have been reports the patch [for CVE-2021-34527] is ineffective, but Microsoft insists it works – provided certain registry keys have the correct values,” noted Dustin Childs, with Trend Micro’s Zero Day Initiative.
“Enterprises should verify these registry keys are configured as intended and get this patch rolled out. It’s also a fine time to disable the Print Spooler service wherever it isn’t needed and restrict the installation of printer drivers to just administrators.”
He also singled out CVE-2021-34448, an actively exploited Scripting Engine memory corruption vulnerability as worthy of a quick patch implementation. Even though there’s no indication of how widespread the attack leveraging it is, he says, it should be treated as critical since it could allow code execution on every supported version of Windows.
“[CVE-2021-34448] is elegant in its simplicity, letting an attacker gain remote code execution just by getting the target to visit a domain. With malicious, yet professional looking, domains carrying valid TLS certificates a regular feature nowadays, seamless compromise would be a trivial matter. Victims could even be attacked by sending .js or .hta files in targeted phishing emails,” noted Kevin Breen, Director of Cyber Threat Research at Immersive Labs.
“A pair of Windows kernel privilege elevation flaws (CVE-2021-33771 and CVE-2021-31979) should also be high on the patch list as they are being actively exploited. These are exactly the type of vulnerabilities in the ransomware attack toolkit, allowing threat actors to boost their user level from user to admin, for greater control over the environment. Admins should keep an eye on existing and new accounts for suspicious activity.”
Another Windows kernel flaw – CVE-2021-34458, potentially leading to remote code execution – has been singled out by Childs.
“This bug impacts systems hosting virtual machines with single root input/output virtualization (SR-IOV) devices. It’s not clear how widespread this configuration is, but considering this bug rates as a CVSS 9.9, it’s not one to ignore. If you have virtual machines in your environment, test and patch quickly.”
Among the less critical vulnerabilities fixed by Microsoft this month is a security feature bypass vulnerability (CVE-2021-34466) in the Windows Hello passwordless authentication system, discovered and detailed by CyberArk researchers.
But security researcher Omer Tsarfati says that Microsoft’s patch may not fully mitigate the issue.
“Based on our preliminary testing of the mitigation, using Enhanced Sign-in Security with compatible hardware limits the attack surface but is dependent on users having specific cameras. Inherent to system design, implicit trust of input from peripheral devices remains. To mitigate this inherent trust issue more comprehensively, the host should validate the integrity of the biometric authentication device before trusting it. We are continuing our investigation,” he told Help Net Security.
Adobe
To mark the July 2021 Patch Tuesday, Adobe has addressed 29 CVEs, most of which are critical.
The Acrobat and Reader security updates should be prioritized, as these (PDF creating and viewing) solutions are more widely used and, consequently, opportunistic attackers are more likely to exploit their flaws than those in Adobe Bridge (digital asset management software) or Adobe Dimension (3D rendering and design software).
The Acrobat and Reader security updates also fix the larger batch of flaws, many of which may allow attackers to achieve arbitrary code execution.
The rest of the security advisories accompanying the other updates can be found here: users should review them and implement the updates at their discretion.
None of the vulnerabilities are actively exploited.
VMware
VMware has plugged two privately reported security holes in VMware ESXi and VMware Cloud Foundation. One is an authentication bypass vulnerability in ESXi’s Small Footprint CIM Broker (CVE-2021-21994), the other one a heap out-of-bounds read issue in the SLP service that could lead to DDoS (CVE-2021-21995).
Users can upgrade to a fixed version or, alternatively, temporarily disable the affected services on the affected host.
SAP
SAP has released 12 new security notes and updated 3 previously released ones. Two of the latter should be given priority (they are, as SAP defines it, “Hot News”), and they cover vulnerabilities in SAP Business Client and SAP NetWeaver AS ABAP and ABAP Platform.
“Since there are only two updated HotNews Notes and two new High Priority Notes, SAP’s July Patch Day can be considered a fairly uneventful patch day,” Onapsis researcher Thomas Fritsch commented, but warned that a note’s CVSS score does not necessarily take into account the worst case scenario.
“The assigned numerical level of severity does not consider the impact of subsequent attacks that could occur or attacks that might gain a broader attack surface through an exploit of the given vulnerability.”
Intel
Intel has released one security advisory on this July 2021 Patch Tuesday: for an escalation of privilege vulnerability (CVE-2021-0144) in the customer build time configuration for the Intel BIOS Shared SW Architecture (BSSA) Design for Test (DFT) feature.
It affects several of its Xeon and Core X-series processor families, and Intel advises affected users to get the latest BIOS firmware version from the system manufacturer.
Mozilla
Mozilla has upgraded Firefox to version 90 and Firefox ESR to version 78.12, simultaneously fixing a variety of security flaws – though none critical.
Firefox 90 also contains some additional security improvements, such as:
- A new version the SmartBlock tracker blocking mechanism built into Firefox Private Browsing and Strict Mode, and
- Support for Fetch Metadata Request Headers, to stymie cross-origin threats – including speculative cross-site execution side channel (aka Spectre) attacks – targeting web applications
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/07/13/july-2021-patch-tuesday/