News: 1634069555

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft Patch Tuesday bug harvest festival comes to town

(2021/10/12)


Microsoft's October Patch Tuesday has arrived with fixes for 71 new CVEs, two patch revisions to address bugs from previous months that just won't die, and three CVEs tied to OpenSSL flaws. That's in addition to eight Edge-Chromium CVEs dealt with earlier this month.

Two of the fresh bugs are rated Critical, 68 are designated Important, and one is rated Low severity.

Four among [1]the overall October harvest have been publicly disclosed, including one from July, an Azure AD security feature bypass vulnerability ( [2]CVE-2021-33781 ). The other holdover from September is [3]CVE-2021-38624 , a Windows key storage provider security feature bypass flaw.

[4]

Microsoft says one of the bugs, a Win32K privilege elevation issue ( [5]CVE-2021-40449 ) is currently being exploited.

[6]

[7]

According to Kaspersky security researchers Costin Raiu and Boris Larin, Kaspersky initially spotted attacks using a privilege elevation exploit on Microsoft Windows servers in late August and early September.

"The exploit had numerous debug strings from an older, publicly known exploit for vulnerability [8]CVE-2016-3309 , but closer analysis revealed that it was a zero-day," said Raiu and Larin in a [9]blog post . "We discovered that it was using a previously unknown vulnerability in the Win32k driver and exploitation relies heavily on a technique to leak the base addresses of kernel modules."

[10]

After Kaspersky reported the zero-day vulnerability to Microsoft, it was designated [11]CVE-2021-40449 .

Avoid a Halloween scare

Zero-Day Initiative's Dustin Childs in a [12]blog post noted that an Exchange Server remote code execution vulnerability ( [13]CVE-2021-26427 ) is likely to get a fair amount of attention because it was reported to Microsoft by the US National Security Agency, even if it's not all that severe on its own. The NSA, America's signals intelligence agency, was last seen shoring up Exchange Server installations [14]back in April . Coincidentally, Microsoft Exchange has been [15]a popular target for state-sponsored hacking groups .

Childs also highlighted two other vulnerabilities, a Microsoft Word remote code execution bug ( [16]CVE-2021-40486 ) and a rich text edit control flaw in Power Apps ( [17]CVE-2021-40454 ) that can be used to expose sensitive information.

"We don’t often highlight information disclosure bugs, but this vulnerability goes beyond just dumping random memory locations," said Childs. "This bug could allow an attacker to recover cleartext passwords from memory, even on Windows 11."

In an email to The Register , Kevin Breen, director of cyber threat research at [18]Immersive Labs , pointed to [19]CVE-2021-40487 , a Microsoft SharePoint remote code execution flaw, as another priority patch.

[20]

"This one requires an authenticated user on the domain, so it will be more difficult for an attacker to exploit; however, gaining remote code execution on a Sharepoint server opens up a lot of avenues for further exploitation," said Breen.

And the best of the rest

[21]Adobe , meanwhile, has prepared [22]six patches addressing 10 CVEs in Adobe Reader, Acrobat Reader for Android, Adobe Campaign Standard, Commerce, Ops-CLI, and Adobe Connect. That's significantly less than the 59 CVEs it tended to [23]last month .

According to Childs, the Acrobat patch repairs four flaws, two of which are rated Critical and two of which are rated Moderate. "The Critical-rated bugs could allow remote code execution while the Moderate-rated bugs could allow a privilege escalation," he said, adding that the Reader for Android fix closes a single path traversal bug that provides an opportunity for code execution.

On Monday, Apple released [24]iOS 15.0.2, and iPadOS 15.0.2 to address a CVE-2021-30883, [25]an actively exploited zero-day bug in the IOMobileFrameBuffer kernel extension.

[26]Apple patches 'actively exploited' iPhone zero-day with iOS 15.0.2 update

[27]Story of the creds-leaking Exchange Autodiscover flaw – the one Microsoft wouldn't fix even after 5 years

[28]Apple warns of arbitrary code execution zero-day being actively exploited on Macs

[29]Break out your emergency change process and patch this ransomware-friendly bug ASAP, says VMware

Finally, SAP released 17 new and revised security patches, three of which have been classified HotNews and one of which has been filed under High Priority. That's a bit less of a dumpster fire than last month's drop with seven HotNews critical fixes. However, one of the HotNews notes refers to repairs to the SAP Business Client's Chromium implementation: It brings Chromium to version 94.0.4606.54 within the client software and fixes 65 browser bugs.

Onapsis security researcher Thomas Fritsch in [30]blog post noted that another of the HotNews designees, SAP Security Note [31]#3101406 , carries a CVSS score of 9.8 and is the most critical of the bugs in the October harvest. The patch addresses an XML External Entity (XEE) Injection vulnerability in SAP Environmental Compliance (SAP EC), he explains, noting that SAP EC supports emission management and compliance relevant processes in industrial environments.

"Given the fact that the assigned CVSS vector indicates a high impact on confidentiality, integrity, and availability, let's assume that there is a wide range of possible exploits," said Fritsch. "In general, an XEE Injection vulnerability is a web security vulnerability that allows an attacker to interfere with an application's processing of XML data." ®

Get our [32]Tech Resources



[1] https://msrc.microsoft.com/update-guide/vulnerability

[2] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-33781

[3] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38624

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YWYFnWJ@Jg0MFVrGqH996wAAAFM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40449

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWYFnWJ@Jg0MFVrGqH996wAAAFM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YWYFnWJ@Jg0MFVrGqH996wAAAFM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://github.com/siberas/CVE-2016-3309_Reloaded/

[9] https://securelist.com/mysterysnail-attacks-with-windows-zero-day/104509/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWYFnWJ@Jg0MFVrGqH996wAAAFM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40449

[12] https://www.zerodayinitiative.com/blog/2021/10/12/the-october-2021-security-update-review

[13] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26427

[14] https://www.theregister.com/2021/04/13/patch_tuesday_april/

[15] https://www.theregister.com/2021/03/03/hafnium_exchange_server_attack/

[16] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40486

[17] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40454

[18] https://www.immersivelabs.com/

[19] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40487

[20] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YWYFnWJ@Jg0MFVrGqH996wAAAFM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[21] https://helpx.adobe.com/security.html

[22] https://helpx.adobe.com/security.html/security/security-bulletin.ug.html

[23] https://www.theregister.com/2021/09/15/microsoft_patch_tuesday/

[24] https://support.apple.com/en-us/HT212846

[25] https://www.theregister.com/2021/10/12/apple_ios_15_0_2_zero_day_patched/

[26] https://www.theregister.com/2021/10/12/apple_ios_15_0_2_zero_day_patched/

[27] https://www.theregister.com/2021/09/27/microsoft_exchange_autodiscover/

[28] https://www.theregister.com/2021/09/24/apple_zero_day/

[29] https://www.theregister.com/2021/09/22/vmware_emergency_vcenter_patch_recommendation/

[30] https://onapsis.com/blog/sap-security-patch-day-october-2021-critical-patches-sap-environmental-compliance-and-sap

[31] https://launchpad.support.sap.com/#/notes/3101406

[32] https://whitepapers.theregister.com/



"Microsoft Patch Tuesday bug harvest festival comes to town"

Pascal Monett

Quick, pause Windows Update for at least 14 days !

Re: "Microsoft Patch Tuesday bug harvest festival comes to town"

Alumoi

Nope, until the next patch patches the current patch. Oh, wait!

Still end to Print Nightmare

Lorribot

No fix for broken printing caused by the broken patch for the broken Spooler service nightmare then. so i can't apply these patches or last months cumulative update or printing stops working so i now have print servers missing two months worth of patches.

"I thought that you said you were 20 years old!"
"As a programmer, yes," she replied,
"And you claimed to be very near two meters tall!"
"You said you were blonde, but you lied!"
Oh, she was a hacker and he was one, too,
They had so much in common, you'd say.
They exchanged jokes and poems, and clever new hacks,
And prompts that were cute or risque'.
He sent her a picture of his brother Sam,
She sent one from some past high school day,
And it might have gone on for the rest of their lives,
If they hadn't met in L.A.
"Your beard is an armpit," she said in disgust.
He answered, "Your armpit's a beard!"
And they chorused: "I think I could stand all the rest
If you were not so totally weird!"
If she had not said what he wanted to hear,
And he had not done just the same,
They'd have been far more honest, and never have met,
And would not have had fun with the game.
-- Judith Schrier, "Face to Face After Six Months of
Electronic Mail"