It’s the second Tuesday of the month, which means the latest security updates from Adobe and Microsoft are released. Take a break from your regularly scheduled activities and join us as we review the details for their latest security offerings.
Adobe Patches for May 2021
For May, Adobe released 12 patches addressing at least 43 CVEs in Experience Manager, InDesign, Illustrator, InCopy, Adobe Genuine Service, Acrobat and Reader, Magento, Creative Cloud Desktop, Media Encoder, Medium, and Animate. Adobe also lists an update for After Effects, but as of now, this link leads to a 404 page rather than a security update. A total of five of these bugs came through the ZDI program.
The update for also stands out. These bugs result from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process.
Beyond the one Reader bug, none of the other vulnerabilities patched by Adobe this month are listed as publicly known or under active attack at the time of release.
Microsoft Patches for May 2021
For May, Microsoft released patches for 55 CVEs in Microsoft Windows, .NET Core and Visual Studio, Internet Explorer (IE), Microsoft Office, SharePoint Server, Open-Source Software, Hyper-V, Skype for Business and Microsoft Lync, and Exchange Server. A total of 13 of these bugs came through the ZDI program. Of these 55 bugs, four are rated as Critical, 50 are rated as Important, and one is listed as Moderate in severity. According to Microsoft, three of these bugs are publicly known but none are listed as under active exploit at the time of release.
Let’s take a closer look at some of the more interesting updates for this month, starting with a bug sure to garner a lot of attention:
- - Hyper-V Remote Code Execution Vulnerability
With a CVSS of 9.9, this bug scores the highest severity rating for this month’s release. However, Microsoft notes an attacker is more likely to abuse this vulnerability for a denial of service in the form of a bugcheck rather than code execution. Because of this, it could be argued that the attack complexity would be high, which changes the CVSS rating to 8.5. That still rates as high severity, but not critical. Still, the bugcheck alone is worth making sure your Hyper-V systems get this update.
- - Windows Wireless Networking Information Disclosure Vulnerability
We don’t normally highlight info disclosure bugs, but this one has the potential to be pretty damaging. This patch fixes a vulnerability that could allow an attacker to disclose the contents of encrypted wireless packets on an affected system. It’s not clear what the range on such an attack would be, but you should assume some proximity is needed. You’ll also note this CVE is from 2020, which could indicate Microsoft has been working on this fix for some time.
Here’s the full list of CVEs released by Microsoft for May 2021:
| CVE | Title | Severity | CVSS | Public | Exploited | Type |
| Common Utilities Remote Code Execution Vulnerability | Important | 7.2 | Yes | No | RCE | |
| HTTP Protocol Stack Remote Code Execution Vulnerability | Critical | 9.8 | No | No | RCE | |
| OLE Automation Remote Code Execution Vulnerability | Critical | 7.8 | No | No | RCE | |
| Dynamics Finance and Operations Cross-site Scripting Vulnerability | Important | 6.1 | No | No | XSS | |
| Microsoft Bluetooth Driver Spoofing Vulnerability | Important | 7.1 | No | No | Spoofing | |
| Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 6.5 | No | No | RCE | |
| Microsoft Exchange Server Spoofing Vulnerability | Important | 6.5 | No | No | Spoofing | |
| Microsoft Office Graphics Remote Code Execution Vulnerability | Important | 7.8 | No | No | RCE | |
| Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 | No | No | RCE | |
| Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 | No | No | RCE | |
| Microsoft SharePoint Information Disclosure Vulnerability | Important | 4.1 | No | No | Info | |
| Microsoft SharePoint Server Information Disclosure Vulnerability | Important | 5.3 | No | No | Info | |
| Microsoft SharePoint Spoofing Vulnerability | Important | 4.6 | No | No | Spoofing | |
| Microsoft SharePoint Spoofing Vulnerability | Important | 7.1 | No | No | Spoofing | |
| Skype for Business and Lync Remote Code Execution Vulnerability | Important | 7.2 | No | No | RCE | |
| Visual Studio Code Remote Code Execution Vulnerability | Important | 7.8 | No | No | RCE | |
| Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability | Important | 7.8 | No | No | RCE | |
| Web Media Extensions Remote Code Execution Vulnerability | Important | 7.8 | No | No | RCE | |
| Windows Container Manager Service Elevation of Privilege Vulnerability | Important | 7.8 | No | No | EoP | |
| Windows Container Manager Service Elevation of Privilege Vulnerability | Important | 7.8 | No | No | EoP | |
| Windows Container Manager Service Elevation of Privilege Vulnerability | Important | 7.8 | No | No | EoP | |
| Windows Desktop Bridge Denial of Service Vulnerability | Important | 5.5 | No | No | DoS | |
| Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 | No | No | EoP | |
| Windows Projected File System FS Filter Driver Information Disclosure Vulnerability | Important | 5.5 | No | No | Info | |
| Windows SMB Client Security Feature Bypass Vulnerability | Important | 4.3 | No | No | SFB | |
| Windows WalletService Elevation of Privilege Vulnerability | Important | 7.8 | No | No | EoP | |
| Windows Wireless Networking Spoofing Vulnerability | Important | 6.5 | No | No | Spoofing | |
| ) had an update checked in to GitHub back in December. If you use the Neural Network Intelligence open-source toolkit, make sure you have the latest version. There are several open-and-own style bugs in various Office components. There are three code execution bugs in Visual Studio Code, but these require a user to open a malicious file in a directory. If an attacker can convince such an act, they can execute their code at the level of the logged-on user. Another RCE was reported by ZDI researcher Hossein Lotfi and impacts the Jet Red Database Engine and Access Connectivity Engine. To completely address this vulnerability, you’ll want to apply the update and restrict access to remote databases. Failing to restrict access can still expose your database to potential SQL adhoc/injection flaws. Microsoft published ) was revised for all versions of Windows. No new advisories were released this month. Looking Ahead The next Patch Tuesday falls on June 8, and we’ll return with details and patch analysis then. Until then, stay safe, happy patching, and may all your reboots be smooth and clean! Vollständiger Original-Bericht Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf thezdi.com. Wie bewertest du diesen Beitrag? 1 Klick Feedback Teilen mit Netzwerk & Team: Community-Analysen & Experten-Meinungen 0Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog. Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf „ Eigene Analyse verfassen“! Community Pulse: Relevanz-Einschätzung 1 Klick Experten-Votum 🔴 Akute Relevanz 0% 🟡 In Evaluierung 0% 🟢 Keine Auswirkung 0% Spannende Innovation 0% Verwandte Story-Cluster & Quellen (Vektor-KI) Tipp: Mit Pfeiltasten [ ← ] und [ → ] blättern
Ähnliche Beiträge
🔍 Verwandte News
Auch interessante Nachrichten The May 2021 Security Update ReviewThematisch verwandte Begriffe: 2021, Security, Update, Review · 6 Treffer ⚠️ Malware / Trojaner / Viren Elastic Security Labs Automating the Security Protections rapid response to malware 🕵️ Sicherheitslücken Elastic Security Labs Detection and response for the actively exploited ProxyShell vulnerabilities 🕵️ Sicherheitslücken GBHackers Security | #1 Glob Roundcube Fixes 12 Security Flaws Including Zero-Click XSS and SSRF Bypass
Laden...
Videos werden geladen ...
Laden...
Beiträge werden geladen ...
Laden...
Videos werden geladen ...
Laden...
Beiträge werden geladen ...
Laden...
Videos werden geladen ...
Laden...
Beiträge werden geladen ...
Laden...
Videos werden geladen ...
Laden...
Beiträge werden geladen ...
Laden...
Videos werden geladen ... 🔖 Gespeicherte Artikel
📂
Keine gespeicherten Artikel vorhanden.
📂 News
⏱️ 3 Min
vor 10 Min
Artikeldaten werden geladen...
tsecurity.de AppOffline-Lesen, Eilmeldungen & 0ms Ladezeit
Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.
Nächster Beitrag
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster:
Security Explorer
Match:
lädt…
Aktivitäten deiner Analystenlädt…
Neues Thema oder Eilmeldung einreichenReiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung. Heiß diskutierte Einreichungen |
SOCIAL SHARE CARD GENERATOR