Exposure Management

Patch Tuesday - April 2021

|Last updated on Apr 14, 2021|1 min read
LinkedInFacebookX
Patch Tuesday - April 2021

Patch Tuesday is here again and there are more Exchange updates to apply! A total of 114 vulnerabilities were fixed this month with more than half of them affecting all versions of Windows, with about half of them being remote code execution bugs, and about a fifth of them being rated as critical by Microsoft. Let's dive in!

New Exchange Server Patches Available

If you were only going to patch one thing today, please let it be this. Exchange Server has been a hot topic since the vulnerabilities announced in the out-of-band advisory back at the beginning of March saw widespread exploitation. The vulnerabilities this month were reported to Microsoft via the NSA in the interest of national security. The Exchange team has also released a very helpful blog post with instructions on how to patch from any version to the latest secure version. While these have not been exploited in the wild at the time of writing it is only a matter of time before someone reverse engineers the patches and gets up to no good.

CVEs: CVE-2021-28310, CVE-2021-28481, CVE-2021-28482, CVE-2021-28483

Windows RPC Runtime

Next up we have a relatively high number of patches in the Windows Remote Procedure Call Runtime. There were 27 remote code execution vulnerabilities fixed this month. Someone was busy finding bugs! The RPC Runtime is available on all versions of Windows so make sure both Servers and Clients get these updates. Many of these are critical (according to the CVSS3 vectors) requiring no user interaction and only network level access.

CVEs:  CVE-2021-28329 to CVE-2021-28339 (please see the list below for a complete list)

Publicly Disclosed and Exploited

Lastly, we have a few vulnerabilities that have been disclosed publicly and one observed in the wild. A few of these are low severity but we rarely see vulnerabilities leveraged by themselves these days. Many attackers have shifted to using exploit chains in order to turn a few low severity bugs into a more complete compromise. Microsoft has also rated a few information disclosure vulnerabilities as "Exploitation More Likely" in SMB Server and the TCP/IP stack.

CVEs: CVE-2021-27091, CVE-2021-28310, CVE-2021-28312, CVE-2021-28437, CVE-2021-28458, CVE-2021-28324, CVE-2021-28442

Summary Tables

Here are this month's patched vulnerabilities split by the product family.

Azure Vulnerabilities

CVEVulnerability TitleExploitedDisclosedCVSS3FAQ
CVE-2021-28458Azure ms-rest-nodeauth Library Elevation of Privilege VulnerabilityNoYes7.8No
CVE-2021-28460Azure Sphere Unsigned Code Execution VulnerabilityNoNo8.1Yes

Browser Vulnerabilities

CVEVulnerability TitleExploitedDisclosedCVSS3FAQ
CVE-2021-21199Chromium: CVE-2021-21199 Use Use after free in AuraNoNoN/AYes
CVE-2021-21198Chromium: CVE-2021-21198 Out of bounds read in IPCNoNoN/AYes
CVE-2021-21197Chromium: CVE-2021-21197 Heap buffer overflow in TabStripNoNoN/AYes
CVE-2021-21196Chromium: CVE-2021-21196 Heap buffer overflow in TabStripNoNoN/AYes
CVE-2021-21195Chromium: CVE-2021-21195 Use after free in V8NoNoN/AYes
CVE-2021-21194Chromium: CVE-2021-21194 Use after free in screen captureNoNoN/AYes

Developer Tools Vulnerabilities

CVEVulnerability TitleExploitedDisclosedCVSS3FAQ
CVE-2021-27064Visual Studio Installer Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-28457Visual Studio Code Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-28469Visual Studio Code Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-28475Visual Studio Code Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-28473Visual Studio Code Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-28477Visual Studio Code Remote Code Execution VulnerabilityNoNo7No
CVE-2021-28472Visual Studio Code Maven for Java Extension Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-28448Visual Studio Code Kubernetes Tools Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-28470Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-28471Remote Development Extension for Visual Studio Code Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-27067Azure DevOps Server and Team Foundation Server Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2021-28459Azure DevOps Server Spoofing VulnerabilityNoNo6.1No

Exchange Server Vulnerabilities

CVEVulnerability TitleExploitedDisclosedCVSS3FAQ
CVE-2021-28480Microsoft Exchange Server Remote Code Execution VulnerabilityNoNo9.8Yes
CVE-2021-28481Microsoft Exchange Server Remote Code Execution VulnerabilityNoNo9.8Yes
CVE-2021-28483Microsoft Exchange Server Remote Code Execution VulnerabilityNoNo9Yes
CVE-2021-28482Microsoft Exchange Server Remote Code Execution VulnerabilityNoNo8.8Yes

Microsoft Office Vulnerabilities

CVEVulnerability TitleExploitedDisclosedCVSS3FAQ
CVE-2021-28453Microsoft Word Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-28450Microsoft SharePoint Denial of Service UpdateNoNo5No
CVE-2021-28452Microsoft Outlook Memory Corruption VulnerabilityNoNo7.1Yes
CVE-2021-28449Microsoft Office Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-28451Microsoft Excel Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-28454Microsoft Excel Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-28456Microsoft Excel Information Disclosure VulnerabilityNoNo5.5Yes

Windows Vulnerabilities

CVEVulnerability TitleExploitedDisclosedCVSS3FAQ
CVE-2021-28442Windows TCP/IP Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2021-28319Windows TCP/IP Driver Denial of Service VulnerabilityNoNo7.5No
CVE-2021-28347Windows Speech Runtime Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-28351Windows Speech Runtime Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-28436Windows Speech Runtime Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-27086Windows Services and Controller App Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-27090Windows Secure Kernel Mode Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-28324Windows SMB Information Disclosure VulnerabilityNoNo7.5Yes
CVE-2021-28325Windows SMB Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2021-28320Windows Resource Manager PSM Service Extension Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-26417Windows Overlay Filter Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-28312Windows NTFS Denial of Service VulnerabilityNoYes3.3No
CVE-2021-27079Windows Media Photo Codec Information Disclosure VulnerabilityNoNo5.7Yes
CVE-2021-28444Windows Hyper-V Security Feature Bypass VulnerabilityNoNo5.7Yes
CVE-2021-28441Windows Hyper-V Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2021-28314Windows Hyper-V Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-26416Windows Hyper-V Denial of Service VulnerabilityNoNo7.7Yes
CVE-2021-28435Windows Event Tracing Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-27088Windows Event Tracing Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-27094Windows Early Launch Antimalware Driver Security Feature Bypass VulnerabilityNoNo4.4No
CVE-2021-28447Windows Early Launch Antimalware Driver Security Feature Bypass VulnerabilityNoNo4.4No
CVE-2021-28438Windows Console Driver Denial of Service VulnerabilityNoNo5.5No
CVE-2021-28311Windows Application Compatibility Cache Denial of Service VulnerabilityNoNo6.5No
CVE-2021-28326Windows AppX Deployment Server Denial of Service VulnerabilityNoNo5.5No
CVE-2021-28310Win32k Elevation of Privilege VulnerabilityYesNo7.8No
CVE-2021-27072Win32k Elevation of Privilege VulnerabilityNoNo7No
CVE-2021-28464VP9 Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-28466Raw Image Extension Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-28468Raw Image Extension Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-27092Azure AD Web Sign-in Security Feature Bypass VulnerabilityNoNo6.8No

Windows Developer Tools Vulnerabilities

CVEVulnerability TitleExploitedDisclosedCVSS3FAQ
CVE-2021-28313Diagnostics Hub Standard Collector Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-28321Diagnostics Hub Standard Collector Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-28322Diagnostics Hub Standard Collector Service Elevation of Privilege VulnerabilityNoNo7.8No

Windows ESU Vulnerabilities

CVEVulnerability TitleExploitedDisclosedCVSS3FAQ
CVE-2021-28316Windows WLAN AutoConfig Service Security Feature Bypass VulnerabilityNoNo4.2No
CVE-2021-28439Windows TCP/IP Driver Denial of Service VulnerabilityNoNo7.5No
CVE-2021-28446Windows Portmapping Information Disclosure VulnerabilityNoNo7.1Yes
CVE-2021-28445Windows Network File System Remote Code Execution VulnerabilityNoNo8.1No
CVE-2021-27095Windows Media Video Decoder Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-28315Windows Media Video Decoder Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-27093Windows Kernel Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-28309Windows Kernel Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-26413Windows Installer Spoofing VulnerabilityNoNo6.2No
CVE-2021-28437Windows Installer Information Disclosure VulnerabilityNoYes5.5Yes
CVE-2021-26415Windows Installer Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-28440Windows Installer Elevation of Privilege VulnerabilityNoNo7No
CVE-2021-28348Windows GDI+ Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-28349Windows GDI+ Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-28350Windows GDI+ Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-28318Windows GDI+ Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-28323Windows DNS Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2021-28328Windows DNS Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2021-28443Windows Console Driver Denial of Service VulnerabilityNoNo5.5No
CVE-2021-28329Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28330Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28331Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28332Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28333Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28334Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28335Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28336Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28337Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28338Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28339Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28343Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28327Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28340Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28341Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28342Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28344Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28345Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28346Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28352Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28353Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28354Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28355Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28356Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28357Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28358Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-28434Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-27091RPC Endpoint Mapper Service Elevation of Privilege VulnerabilityNoYes7.8No
CVE-2021-27096NTFS Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-28317Microsoft Windows Codecs Library Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-27089Microsoft Internet Messaging API Remote Code Execution VulnerabilityNoNo7.8No

Summary Graphs

output_18_2.pngoutput_20_2.pngoutput_26_1.pngoutput_25_1.png

Related blog posts