Detection and Response

Patch Tuesday - July 2021

|Last updated on Jul 13, 2021|1 min read
LinkedInFacebookX
Patch Tuesday - July 2021

Microsoft has patched another 117 CVEs, returning to volumes seen in early 2021 and most of 2020. It would appear that the recent trend of approximately 50 vulnerability fixes per month was not indicative of a slowing pace. This month there were 13 vulnerabilities rated Critical with nearly the rest being rated Important. Thankfully, none of the updates published today require additional steps to remediate, so administrators should be able to rely on their normal patching process. Once CVE-2021-34527 has been remediated, priority should be to patch public facing DNS and Exchange servers, followed by Workstations, SharePoint servers, and finally Office applications.

It seems like the PrintNightmare is nearly over. While the past two weeks have been a frenzy for the security community there has been no new information since the end of last week when Microsoft made a final revision to their guidance on CVE-2021-34527. If you haven’t patched this yet, this is your daily reminder. For further details please see our blog on the topic.

Multiple Critical DNS Vulnerabilities Patched

Administrators should focus their efforts on the 11 vulnerabilities in Windows DNS server to reduce the most risk. The two most important of these vulnerabilities are CVE-2021-34494 and CVE-2021-33780. Exploitation of either of these vulnerabilities would result in Remote Code Execution with SYSTEM privileges without any user interaction via the network. Given the network exposure of DNS servers these vulnerabilities could prove to be troublesome if an exploit were to be developed. Microsoft lists CVE-2021-33780 as “Exploitation More Likely” so it may only be a matter of time before attackers attempt to make use of these flaws.

New Exchange Updates Available

Only 4 of the 7 Exchange CVEs being disclosed this month are new. The two most severe vulnerabilities were patched in back in April and were mistakenly not disclosed. This means that if you applied the April 2021 updates you will not need to take any action for CVE-2021-34473, CVE-2021-34523, or CVE-2021-33766. Of the 4 newly patched vulnerabilities the most notable is CVE-2021-31206, a remote code execution flaw discovered in the recent Pwn2Own competition.

Scripting Engine Exploited in the Wild

Exploitation of CVE-2021-34448 has been observed in the wild by researchers. There are no details on the frequency or spread of this exploit. This vulnerability requires the user to visit a link to download a malicious file. As with other vulnerabilities that require user interaction, strong security hygiene is the first line of defense.

Summary Tables

Here are this month's patched vulnerabilities split by the product family.

Apps Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-33753Microsoft Bing Search Spoofing VulnerabilityNoNo4.7Yes

Developer Tools Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-34528Visual Studio Code Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-34529Visual Studio Code Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-34477Visual Studio Code .NET Runtime Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-33767Open Enclave SDK Elevation of Privilege VulnerabilityNoNo8.2Yes
CVE-2021-34479Microsoft Visual Studio Spoofing VulnerabilityNoNo7.8No

Exchange Server Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-34473Microsoft Exchange Server Remote Code Execution VulnerabilityNoYes9.1No
CVE-2021-31206Microsoft Exchange Server Remote Code Execution VulnerabilityNoNo7.6Yes
CVE-2021-31196Microsoft Exchange Server Remote Code Execution VulnerabilityNoNo7.2No
CVE-2021-34523Microsoft Exchange Server Elevation of Privilege VulnerabilityNoYes9No
CVE-2021-33768Microsoft Exchange Server Elevation of Privilege VulnerabilityNoNo8Yes
CVE-2021-34470Microsoft Exchange Server Elevation of Privilege VulnerabilityNoNo8Yes
CVE-2021-33766Microsoft Exchange Information Disclosure VulnerabilityNoNo7.3Yes

Microsoft Dynamics Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-34474Dynamics Business Central Remote Code Execution VulnerabilityNoNo8Yes

Microsoft Office Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-34452Microsoft Word Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-34517Microsoft SharePoint Server Spoofing VulnerabilityNoNo5.3No
CVE-2021-34520Microsoft SharePoint Server Remote Code Execution VulnerabilityNoNo8.1No
CVE-2021-34467Microsoft SharePoint Server Remote Code Execution VulnerabilityNoNo7.1No
CVE-2021-34468Microsoft SharePoint Server Remote Code Execution VulnerabilityNoNo7.1Yes
CVE-2021-34519Microsoft SharePoint Server Information Disclosure VulnerabilityNoNo5.3Yes
CVE-2021-34469Microsoft Office Security Feature Bypass VulnerabilityNoNo8.2Yes
CVE-2021-34451Microsoft Office Online Server Spoofing VulnerabilityNoNo5.3Yes
CVE-2021-34501Microsoft Excel Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-34518Microsoft Excel Remote Code Execution VulnerabilityNoNo7.8Yes

SQL Server Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-31984Power BI Remote Code Execution VulnerabilityNoNo7.6Yes

System Center Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-34464Microsoft Defender Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-34522Microsoft Defender Remote Code Execution VulnerabilityNoNo7.8Yes

Windows Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-33772Windows TCP/IP Driver Denial of Service VulnerabilityNoNo7.5No
CVE-2021-34490Windows TCP/IP Driver Denial of Service VulnerabilityNoNo7.5No
CVE-2021-33744Windows Secure Kernel Mode Security Feature Bypass VulnerabilityNoNo5.3No
CVE-2021-33763Windows Remote Access Connection Manager Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-34454Windows Remote Access Connection Manager Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-33761Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-33773Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-34445Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-33743Windows Projected File System Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-34493Windows Partition Management Driver Elevation of Privilege VulnerabilityNoNo6.7No
CVE-2021-33740Windows Media Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-34458Windows Kernel Remote Code Execution VulnerabilityNoNo9.9Yes
CVE-2021-34508Windows Kernel Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-33771Windows Kernel Elevation of Privilege VulnerabilityYesNo7.8No
CVE-2021-31961Windows InstallService Elevation of Privilege VulnerabilityNoNo6.1Yes
CVE-2021-34450Windows Hyper-V Remote Code Execution VulnerabilityNoNo8.5Yes
CVE-2021-33758Windows Hyper-V Denial of Service VulnerabilityNoNo7.7No
CVE-2021-33755Windows Hyper-V Denial of Service VulnerabilityNoNo6.3No
CVE-2021-34466Windows Hello Security Feature Bypass VulnerabilityNoNo5.7Yes
CVE-2021-34438Windows Font Driver Host Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-34455Windows File History Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-33774Windows Event Tracing Elevation of Privilege VulnerabilityNoNo7No
CVE-2021-33759Windows Desktop Bridge Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-34525Windows DNS Server Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-34461Windows Container Isolation FS Filter Driver Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-34488Windows Console Driver Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-33784Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-34462Windows AppX Deployment Extensions Elevation of Privilege VulnerabilityNoNo7No
CVE-2021-34459Windows AppContainer Elevation Of Privilege VulnerabilityNoNo7.8No
CVE-2021-33785Windows AF_UNIX Socket Provider Denial of Service VulnerabilityNoNo7.5No
CVE-2021-33779Windows ADFS Security Feature Bypass VulnerabilityNoYes8.1Yes
CVE-2021-34491Win32k Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-34449Win32k Elevation of Privilege VulnerabilityNoNo7No
CVE-2021-34509Storage Spaces Controller Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-34460Storage Spaces Controller Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-34510Storage Spaces Controller Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-34512Storage Spaces Controller Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-34513Storage Spaces Controller Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-33751Storage Spaces Controller Elevation of Privilege VulnerabilityNoNo7No
CVE-2021-34521Raw Image Extension Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-34439Microsoft Windows Media Foundation Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-34503Microsoft Windows Media Foundation Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-33760Media Foundation Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-31947HEVC Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-33775HEVC Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-33776HEVC Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-33777HEVC Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-33778HEVC Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-34489DirectWrite Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-33781Active Directory Security Feature Bypass VulnerabilityNoYes8.1No

Windows ESU Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-31183Windows TCP/IP Driver Denial of Service VulnerabilityNoNo7.5No
CVE-2021-33757Windows Security Account Manager Remote Protocol Security Feature Bypass VulnerabilityNoNo5.3Yes
CVE-2021-33783Windows SMB Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2021-34507Windows Remote Assistance Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2021-34457Windows Remote Access Connection Manager Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-34456Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-34527Windows Print Spooler Remote Code Execution VulnerabilityYesYes8.8Yes
CVE-2021-34497Windows MSHTML Platform Remote Code Execution VulnerabilityNoNo6.8Yes
CVE-2021-34447Windows MSHTML Platform Remote Code Execution VulnerabilityNoNo6.8Yes
CVE-2021-33786Windows LSA Security Feature Bypass VulnerabilityNoNo8.1Yes
CVE-2021-33788Windows LSA Denial of Service VulnerabilityNoNo7.5No
CVE-2021-33764Windows Key Distribution Center Information Disclosure VulnerabilityNoNo5.9Yes
CVE-2021-34500Windows Kernel Memory Information Disclosure VulnerabilityNoNo6.3Yes
CVE-2021-31979Windows Kernel Elevation of Privilege VulnerabilityYesNo7.8No
CVE-2021-34514Windows Kernel Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-33765Windows Installer Spoofing VulnerabilityNoNo6.2No
CVE-2021-34511Windows Installer Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-34446Windows HTML Platforms Security Feature Bypass VulnerabilityNoNo8No
CVE-2021-34496Windows GDI Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-34498Windows GDI Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-33749Windows DNS Snap-in Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2021-33750Windows DNS Snap-in Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2021-33752Windows DNS Snap-in Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2021-33756Windows DNS Snap-in Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2021-34494Windows DNS Server Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2021-33780Windows DNS Server Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2021-33746Windows DNS Server Remote Code Execution VulnerabilityNoNo8No
CVE-2021-33754Windows DNS Server Remote Code Execution VulnerabilityNoNo8No
CVE-2021-34442Windows DNS Server Denial of Service VulnerabilityNoNo7.5Yes
CVE-2021-34444Windows DNS Server Denial of Service VulnerabilityNoNo6.5Yes
CVE-2021-34499Windows DNS Server Denial of Service VulnerabilityNoNo6.5No
CVE-2021-33745Windows DNS Server Denial of Service VulnerabilityNoNo6.5Yes
CVE-2021-34492Windows Certificate Spoofing VulnerabilityNoYes8.1No
CVE-2021-33782Windows Authenticode Spoofing VulnerabilityNoNo5.5No
CVE-2021-34504Windows Address Book Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-34516Win32k Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-34448Scripting Engine Memory Corruption VulnerabilityYesNo6.8Yes
CVE-2021-34441Microsoft Windows Media Foundation Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-34440GDI+ Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-34476Bowser.sys Denial of Service VulnerabilityNoNo7.5No

Summary Graphs

output_18_2.pngoutput_20_2.pngoutput_26_1.pngoutput_25_1.png

Related blog posts