Exposure Management

Patch Tuesday - May 2021

|Last updated on May 11, 2021|1 min read
LinkedInFacebookX
Patch Tuesday - May 2021

Here we are again with another installment of Patch Tuesday. When compared to the past few months this one feels a bit light both in severity and number of vulnerabilities addressed. Microsoft has only released patches for 55 CVEs this month, less than half of the usual volume, with only 4 of them being scored as critical. Let's dive into the details.

HTTP Protocol Stack Remote Code Execution Vulnerability - CVE-2021-31166

The hottest vulnerability this month is in the HTTP.sys library. If an attacker has network access to a webserver running on an unpatched asset they may be able to send a specially crafted packet which could result in RCE. This was found internally by Microsoft and has not yet been observed in the wild. However, it is only a matter of time before someone figures out how to craft that special packet and we start to see widespread use against Windows 10 and Windows Server machines. Rated at 9.8, this potentially wormable vulnerability should be a high priority for remediation.

Hyper-V Remote Code Execution - CVE-2021-28476

There is some debate whether this vulnerability deserves its assigned 9.9 severity score. The limited details indicate that the most likely use of this bug is to cause a DoS on the Hyper-V host. This can cause a good amount of trouble for anyone running virtual machines but is not as damaging as the theoretical RCE this vulnerability could provide. In either case this is a good patch to put at the top of the todo-list.

Exchange Server Security Feature Bypass - CVE-2021-31207

Not to be outdone, Exchange Server is back again with yet another patch. This one is not nearly as high profile as the recent vulnerability which saw widespread use, but still an important patch to apply given that Exchange Servers are almost always exposed to the internet. There are a few other less severe vulnerabilities this month for Exchange which were disclosed at Pwn2Own in April. We expect to see a continued focus on Exchange Server in the months to come.

Summary Tables

Azure Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-31936Microsoft Accessibility Insights for Web Information Disclosure VulnerabilityNoNo7.4Yes

Browser ESU Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-26419Scripting Engine Memory Corruption VulnerabilityNoNo7.5Yes

Developer Tools Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-27068Visual Studio Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-31213Visual Studio Code Remote Containers Extension Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-31211Visual Studio Code Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-31214Visual Studio Code Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-31204.NET and Visual Studio Elevation of Privilege VulnerabilityNoYes7.3No

Exchange Server Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-31209Microsoft Exchange Server Spoofing VulnerabilityNoNo6.5Yes
CVE-2021-31207Microsoft Exchange Server Security Feature Bypass VulnerabilityNoYes6.6Yes
CVE-2021-31198Microsoft Exchange Server Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-31195Microsoft Exchange Server Remote Code Execution VulnerabilityNoNo6.5No

Microsoft Dynamics Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-28461Dynamics Finance and Operations Cross-site Scripting VulnerabilityNoNo6.1No

Microsoft Office Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-26421Skype for Business and Lync Spoofing VulnerabilityNoNo6.5No
CVE-2021-26422Skype for Business and Lync Remote Code Execution VulnerabilityNoNo7.2No
CVE-2021-28478Microsoft SharePoint Spoofing VulnerabilityNoNo7.6No
CVE-2021-31172Microsoft SharePoint Spoofing VulnerabilityNoNo7.1No
CVE-2021-26418Microsoft SharePoint Spoofing VulnerabilityNoNo4.6No
CVE-2021-28474Microsoft SharePoint Server Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2021-31173Microsoft SharePoint Server Information Disclosure VulnerabilityNoNo5.3Yes
CVE-2021-31181Microsoft SharePoint Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-31171Microsoft SharePoint Information Disclosure VulnerabilityNoNo4.1Yes
CVE-2021-31175Microsoft Office Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-31176Microsoft Office Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-31177Microsoft Office Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-31179Microsoft Office Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-31178Microsoft Office Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-31180Microsoft Office Graphics Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-31174Microsoft Excel Information Disclosure VulnerabilityNoNo5.5Yes

Open Source Software Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-31200Common Utilities Remote Code Execution VulnerabilityNoYes7.2Yes

Windows Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-31187Windows WalletService Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-31205Windows SMB Client Security Feature Bypass VulnerabilityNoNo4.3Yes
CVE-2021-31191Windows Projected File System FS Filter Driver Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-31192Windows Media Foundation Core Remote Code Execution VulnerabilityNoNo7.3No
CVE-2021-31170Windows Graphics Component Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-31185Windows Desktop Bridge Denial of Service VulnerabilityNoNo5.5No
CVE-2021-31165Windows Container Manager Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-31167Windows Container Manager Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-31168Windows Container Manager Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-31169Windows Container Manager Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-31208Windows Container Manager Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-31190Windows Container Isolation FS Filter Driver Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-28479Windows CSC Service Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-28465Web Media Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-31166HTTP Protocol Stack Remote Code Execution VulnerabilityNoNo9.8Yes

Windows ESU Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2020-24588Windows Wireless Networking Spoofing VulnerabilityNoNo6.5No
CVE-2020-26144Windows Wireless Networking Spoofing VulnerabilityNoNo6.5No
CVE-2020-24587Windows Wireless Networking Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2021-31193Windows SSDP Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-31186Windows Remote Desktop Protocol (RDP) Information Disclosure VulnerabilityNoNo7.4Yes
CVE-2021-31188Windows Graphics Component Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-31194OLE Automation Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-31184Microsoft Windows Infrared Data Association (IrDA) Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-31182Microsoft Bluetooth Driver Spoofing VulnerabilityNoNo7.1No
CVE-2021-28476Hyper-V Remote Code Execution VulnerabilityNoNo9.9Yes

Windows Microsoft Office ESU Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-28455Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution VulnerabilityNoNo8.8Yes

Summary Graphs

output_18_2.pngoutput_20_2.pngoutput_25_1.pngoutput_26_1.png

Related blog posts