ZeroHour
Cisco Talospublished ()ingested

Microsoft Patch Tuesday for May 2021 — Snort rules and prominent vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-31166
Use-After-Free RCE in Microsoft Windows HTTP Protocol Stack (http.sys)

CVE-2021-31166 is a use-after-free vulnerability (CWE-416) in the Microsoft HTTP Protocol Stack, the kernel-mode HTTP service (http.sys) used by Windows components including IIS and WinRM. A remote, unauthenticated attacker can trigger the flaw by sending specially crafted network packets to a service that listens through http.sys, and reporting indicates WinRM servers are also impacted. Successful exploitation yields remote code execution in the kernel context, with full compromise potential (high confidentiality, integrity and availability impact), consistent with the wormable classification in vendor-adjacent reporting. Affected platforms are Windows 10 versions 2004 and 20H2 and Windows Server versions 2004 and 20H2, which were the current shipping Windows versions at the May 2021 Patch Tuesday release where the fix appeared. The issue is tracked in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-06) and carries a near-certain EPSS exploitation probability (~99.8%), indicating active exploitation in the wild.

Do: Apply the May 2021 Patch Tuesday security updates for Windows 10 and Windows Server versions 2004 and 20H2, prioritizing internet-facing systems running IIS, WinRM, or other http.sys-based listeners. As an interim mitigation, restrict inbound access to HTTP and WinRM endpoints at the firewall. Confirm remediation by verifying the OS build includes the May 2021 cumulative update, and check the CISA KEV catalog action (apply updates per vendor instructions).

9.8100% KEV
  • Microsoft Windows 10 version 2004
  • Microsoft Windows 10 version 20H2
  • Microsoft Windows Server version 2004
  • +2 more
masswell over 1,000,000 vulnerable systems (tens of millions of Windows 10 2004/20H2 installs, with likely hundreds of thousands of internet-exposed servers via…
CVE-2021-31194
+1 in the same advisory: …31170
OLE Automation Remote Code Execution Vulnerability

OLE Automation Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.8
group max
2%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
Full article510 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, May 11, 2021 14:32

By Jon Munshaw, with contributions from Chris Neal.

Microsoft released its monthly security update Tuesday, disclosing 55 vulnerabilities across its suite of products, the fewest in any month since January 2020.

There are only three critical vulnerabilities patched in this month, while two are of “moderate” severity and the rest are “important.” All three critical vulnerabilities, however, are considered "more likely” to be exploited, according to Microsoft.

This month’s security update provides patches for several major pieces of software, including Microsoft Office, SharePoint and Windows’ wireless networking. For a full rundown of these CVEs, head to Microsoft’s security update page.

Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilities. For complete details, check out the latest Snort advisory here.

The most serious vulnerability exists in the HTTP protocol stack. An unauthenticated attacker could exploit CVE-2021-31166 by sending a specially crafted packet to a targeted server. If successful, the adversary could gain the ability to execute remote code on the targeted server.

According to Microsoft, the vulnerability is wormable and the company “recommends prioritizing the patching of affected servers.” It has a CVSS severity score of 9.8 out of 10. Microsoft stated in their advisory that it would be relatively easy for an attacker to exploit this vulnerability, as it is considered to be of “low” complexity.

Another critical remote code execution vulnerability, CVE-2021-26419, exists in Internet Explorer’s scripting engine. An attacker could exploit this vulnerability by tricking the user to visit a specially crafted website. Alternatively, they could also embed an ActiveX control marked “safe for initialization” in an application or Microsoft Office document that utilizes Internet Explorer’s rendering engine, and then trick a user into opening that file.

The third critical vulnerability exists in OLE Automation, an inter-process communication mechanism. CVE-2021-31194 could allow an attacker to execute remote code on the targeted machine, without any user interaction required.

Cisco Talos would also like to specifically highlight CVE-2021-31170, an elevation of privilege vulnerability in Windows Graphics Component. A successful of attacker could use this vulnerability to gain greater permissions on a targeted machine and use that in additional attacks. Microsoft considers this vulnerability to be “important,” though the company states in its advisory that exploitation is “more likely.”

A complete list of all the vulnerabilities Microsoft disclosed this month is available on its update page.

In response to these vulnerability disclosures, Talos is releasing a new SNORTⓇ rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Firepower customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.

The rules included in this release that protect against the exploitation of many of these vulnerabilities are 57539, 57540, 57542 - 57545 and 57548 - 57550.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-for-may-2021/