ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews1

Update Your Windows Computers to Patch 6 New In-the-Wild Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-21224
Type Confusion RCE in Google Chrome/Chromium V8 JavaScript Engine

CVE-2021-21224 is a type confusion vulnerability (CWE-843) in V8, the JavaScript engine used by Google Chrome and Chromium. An attacker triggers it by luring a user to open a crafted HTML page, causing V8 to mishandle object types during execution. Successful exploitation yields arbitrary code execution inside the Chrome renderer's sandbox, typically chained with a separate sandbox escape for full host compromise. Anyone running Google Chrome prior to 90.0.4430.85, or Chromium as packaged by Debian and Fedora, is affected. Exploitation is confirmed in the wild: Google shipped the fix in April 2021 after active attacks, a public PoC exists (crbug.com/1195777), the bug was observed in exploit-kit attack chains, EPSS assigns an 84% probability of near-term exploitation, and CISA added it to the KEV catalog on 2021-11-03.

Do: Update Google Chrome to 90.0.4430.85 or later immediately; Debian and Fedora users should apply the chromium package updates issued by their vendors, per CISA KEV required actions. There is no strong workaround short of disabling JavaScript or restricting browsing to trusted sites. Treat this as urgent, since the flaw was already used in real attacks and exploit-kit chains, where it was typically paired with a sandbox escape for full system compromise.

8.884% KEV PoC
  • google chrome prior to 90.0.4430.85 (fixed in 90.0.4430.85)
  • debian linux (chromium package) Chromium builds prior to upstream fix 90.0.4430.85; fixed package versions not specified in source data
  • fedoraproject fedora (chromium package) Chromium builds prior to upstream fix 90.0.4430.85; fixed package versions not specified in source data
masson the order of billions of users (Chrome's global install base exceeds 1 billion desktops; Chromium additionally ships in Debian and Fedora)
CVE-2021-28550
Use-After-Free RCE in Adobe Acrobat and Reader

CVE-2021-28550 is a use-after-free memory corruption flaw in Adobe Acrobat DC and Acrobat Reader DC that an unauthenticated attacker can trigger by getting a victim to open a malicious PDF file. Successful exploitation allows arbitrary code execution in the context of the current user, giving the attacker the privileges of that user on the affected machine. Anyone running Acrobat or Acrobat Reader DC at or below versions 2021.001.20150, 2020.001.30020, or 2017.011.30194 is affected. The flaw was exploited as a zero-day in targeted attacks — Microsoft reported it being chained with Windows zero-days by an Austrian company's operators — and it is listed in CISA's Known Exploited Vulnerabilities catalog as of November 3, 2021. CISA's required action is to apply vendor updates, and defenders should treat exploited, user-targeted PDF attacks as the primary risk.

Do: Upgrade Acrobat and Acrobat Reader DC to versions later than 2021.001.20150, 2020.001.30020, and 2017.011.30194 on the respective tracks, per Adobe's May 2021 update and the CISA KEV required action. Until patched, avoid opening PDFs from untrusted sources and consider email-gateway filtering or sandboxing of PDF attachments. Check endpoint inventory for the affected version ranges and prioritize systems of users who handle unsolicited documents.

8.852% KEV
  • adobe Acrobat Reader DC 2021.001.20150 and earlier; 2020.001.30020 and earlier; 2017.011.30194 and earlier
  • adobe Acrobat DC 2021.001.20150 and earlier; 2020.001.30020 and earlier; 2017.011.30194 and earlier
  • adobe Acrobat affected per CISA (see DC ranges above)
  • +1 more
masshundreds of millions of installations (Acrobat Reader is the world's most widely deployed PDF viewer)
CVE-2021-31199
+1 in the same advisory: …31201
Elevation of Privilege in Microsoft Enhanced Cryptographic Provider (Windows)

CVE-2021-31199 is an elevation-of-privilege vulnerability in the Microsoft Enhanced Cryptographic Provider, a core Windows component that provides cryptographic services to applications. It carries a CVSS 3.1 score of 5.2 (AV:L/AC:L/PR:L/UI:N/S:C), meaning it is triggered by an attacker who already runs low-privileged code locally on a vulnerable Windows system, with no user interaction required, and lets the attacker break out of the intended security scope to gain elevated privileges. The gain is higher privileges on the compromised host, typically used as a stepping stone in a broader intrusion or malware delivery chain. Exposure is broad: any unpatched Windows 7, 8.1, RT 8.1, Windows 10 (versions 1507 through 21H1), Windows Server 2008, or Windows Server 2004 system is affected, since the provider ships with Windows itself. Exploitation is confirmed in the wild: it was one of the actively exploited Windows zero-days fixed in Microsoft's mid-2021 Patch Tuesday release (part of the six/seven-zero-day coverage), Microsoft attributed targeted attacks to the Austrian firm DSIRF using its Subzero surveillance malware, and the flaw was added to CISA's KEV on 2021-11-03; EPSS estimates a 3.0% chance of exploitation in the next 30 days (86th percentile) and no public PoC is known.

Do: Apply Microsoft's security updates (the monthly Patch Tuesday cumulative updates covering this CVE) per vendor instructions for every in-scope Windows version — the flaw is in CISA KEV, so patching is mandatory for federal agencies and there is no documented workaround. Verify hosts have received the updated cumulative update, prioritizing multi-user endpoints, RDP/terminal servers, and workstations where untrusted code runs; if patching is delayed, hunt for signs of targeted intrusion consistent with DSIRF/Subzero activity.

5.23% KEV
  • microsoft Windows 10 1507, 1607, 1809, 1909, 2004, 20H2, 21H1
  • microsoft Windows 7 all supported builds at time of disclosure
  • microsoft Windows 8.1 all supported builds
  • +3 more
mass≈1 billion+ Windows devices (Windows 10 alone had over 1 billion active devices, and the affected set also includes Windows 7/8.1/RT 8.1 and Windows Server…
CVE-2021-33739
+3 in the same advisory: …33742 …31956 …31955
Privilege Escalation in Microsoft Windows Desktop Window Manager (DWM) Core Library

CVE-2021-33739 is an elevation-of-privilege vulnerability in the Microsoft Desktop Window Manager (DWM) Core Library, the component that composites the Windows graphical desktop. A local attacker who can already execute code on a vulnerable machine — for example via a malicious application, an Office payload, or a chained remote code execution bug — can exploit the flaw in DWM to gain elevated privileges on the system. Successful exploitation yields high-impact results (CVSS 8.4, high for confidentiality, integrity and availability), and the bug is typically used to break out of a low-privileged context or complete a full compromise chain. Affected systems are Windows 10 versions 1909, 2004, 20H2 and 21H1, and Windows Server versions 2004 and 20H2, prior to the June 2021 security updates. The flaw was one of six zero-days Microsoft confirmed as actively exploited in the June 2021 Patch Tuesday release; it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 and carries a 6.6% EPSS (93rd percentile), although no public PoC is known and ransomware use is undetermined.

Do: Apply the June 2021 (or later) Windows cumulative updates on Windows 10 1909/2004/20H2/21H1 and Windows Server 2004/20H2, consistent with CISA's required action to apply vendor updates. Because this is a local privilege escalation, prioritize hosts where untrusted or multi-user code runs (VDI, RDS, kiosks, jump servers) and environments with KEV-mandated remediation deadlines. Verify patch status against the June 2021 release, since the bug was confirmed exploited in the wild.

8.4
group max
7% KEV
  • microsoft Windows 10 1909 (pre-June 2021 Patch Tuesday updates)
  • microsoft Windows 10 2004 (pre-June 2021 Patch Tuesday updates)
  • microsoft Windows 10 20H2 (pre-June 2021 Patch Tuesday updates)
  • +3 more
masshundreds of millions of endpoints (Windows 10's installed base exceeds 1 billion devices; builds 1909 through 21H1 were the dominant Windows 10 releases in…
Full article581 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJun 09, 2021

Microsoft on Tuesday released another round of security updates for Windows operating system and other supported software, squashing 50 vulnerabilities, including six zero-days that are said to be under active attack.

The flaws were identified and resolved in Microsoft Windows, .NET Core and Visual Studio, Microsoft Office, Microsoft Edge (Chromium-based and EdgeHTML), SharePoint Server, Hyper-V, Visual Studio Code - Kubernetes Tools, Windows HTML Platform, and Windows Remote Desktop.

Of these 50 bugs, five are rated Critical, and 45 are rated Important in severity, with three of the issues publicly known at the time of release. The vulnerabilities that being actively exploited are listed below -

  • CVE-2021-33742 (CVSS score: 7.5) - Windows MSHTML Platform Remote Code Execution Vulnerability
  • CVE-2021-33739 (CVSS score: 8.4) - Microsoft DWM Core Library Elevation of Privilege Vulnerability
  • CVE-2021-31199 (CVSS score: 5.2) - Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
  • CVE-2021-31201 (CVSS score: 5.2) - Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
  • CVE-2021-31955 (CVSS score: 5.5) - Windows Kernel Information Disclosure Vulnerability
  • CVE-2021-31956 (CVSS score: 7.8) - Windows NTFS Elevation of Privilege Vulnerability

Microsoft didn't disclose the nature of the attacks, how widespread they are, or the identities of the threat actors exploiting them. But the fact that four of the six flaws are privilege escalation vulnerabilities suggests that attackers could be leveraging them as part of an infection chain to gain elevated permissions on the targeted systems to execute malicious code or leak sensitive information.

The Windows maker also noted that both CVE-2021-31201 and CVE-2021-31199 address flaws related to CVE-2021-28550, an arbitrary code execution vulnerability rectified by Adobe last month that it said was being "exploited in the wild in limited attacks targeting Adobe Reader users on Windows."

Google's Threat Analysis Group, which has been acknowledged as having reported CVE-2021-33742 to Microsoft, said "this seem[s] to be a commercial exploit company providing capability for limited nation state Eastern Europe / Middle East targeting."

Russian cybersecurity firm Kaspersky, for its part, detailed that CVE-2021-31955 and CVE-2021-31956 were abused in a Chrome zero-day exploit chain (CVE-2021-21224) in a series of highly targeted attacks against multiple companies on April 14 and 15. The intrusions were attributed to a new threat actor dubbed "PuzzleMaker."

"While we were not able to retrieve the exploit used for remote code execution (RCE) in the Chrome web browser, we were able to find and analyze an elevation of privilege (EoP) exploit that was used to escape the sandbox and obtain system privileges," Kaspersky Lab researchers said.

Elsewhere, Microsoft fixed numerous remote code execution vulnerabilities spanning Paint 3D, Microsoft SharePoint Server, Microsoft Outlook, Microsoft Office Graphics, Microsoft Intune Management Extension, Microsoft Excel, and Microsoft Defender, as well as several privilege escalation flaws in Microsoft Edge, Windows Filter Manager, Windows Kernel, Windows Kernel-Mode Driver, Windows NTLM Elevation, and Windows Print Spooler.

To install the latest security updates, Windows users can head to Start > Settings > Update & Security > Windows Update or by selecting Check for Windows updates.

Software Patches From Other Vendors

Alongside Microsoft, a number of other vendors have also released a slew of patches on Tuesday, including —

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/06/update-your-windows-computers-to-patch.html