Exposure Management

Patch Tuesday - August 2021

|Last updated on Aug 11, 2021|1 min read
LinkedInFacebookX
Patch Tuesday - August 2021

Hot off the press, it’s another issue of the Patch Tuesday blog! While the number of vulnerabilities is low this month, there are a number of high risk items administrators will want to patch right away including a few that will require additional remediation steps. This Patch Tuesday also includes updates for three vulnerabilities that were publicly disclosed earlier this month. Let’s jump in.

Windows Elevation of Privilege Vulnerability aka HiveNightmare/SeriousSAM

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36934
With a public proof-of-concept having been available for some time, administrators should prioritize taking action on CVE-2021-36934. Remediation for this vulnerability requires volume shadow copies for system files to be deleted. This is due to the nature of the vulnerability, as the files with the vulnerable permissions could be restored from a backup and accessed even after the patch is installed. Microsoft indicates they took caution not to delete users' backups, but the trade-off is that customers will need to do the chore themselves. We've updated our blog post with this additional information.

Windows LSA Spoofing Vulnerability aka ADV210003

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36942
Another high priority action for patching teams is CVE-2021-36942. This update patches one of the vectors used in the PetitPotam attack. After applying this update there are additional configurations required in order to protect systems from other attack vectors using registry keys. The InsightVM team has included detection for the registry keys needed to enable EPA and SMB Signing in addition to the normal update.  Please see our blog post for more information.

Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-26432
While Microsoft has not offered up any details for this vulnerability we can glean some info from the CVSS information. This remote code execution vulnerability is reachable from the network service with no authentication or user action required. There may not be an exploit available for this yet, but Microsoft indicates that “Exploitation [is] more likely”. Put this update near the top of your TODO list.

Windows TCP/IP Remote Code Execution Vulnerability

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-26424
Last on our list is a vulnerability that can result in remote execution on a Hyper-V host via the IPv6 networking stack. If Hyper-V is used in your environment this should be first on your list this month.

Summary Graphs

output_26_1.pngoutput_25_1.pngoutput_20_2.pngoutput_18_2.png

Summary Tables

Azure Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-36949Microsoft Azure Active Directory Connect Authentication Bypass VulnerabilityNoNo7.1Yes
CVE-2021-26428Azure Sphere Information Disclosure VulnerabilityNoNo4.4Yes
CVE-2021-26429Azure Sphere Elevation of Privilege VulnerabilityNoNo7.7Yes
CVE-2021-26430Azure Sphere Denial of Service VulnerabilityNoNo6Yes
CVE-2021-33762Azure CycleCloud Elevation of Privilege VulnerabilityNoNo7No
CVE-2021-36943Azure CycleCloud Elevation of Privilege VulnerabilityNoNo4No

Browser Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-30597Chromium: CVE-2021-30597 Use after free in Browser UINoNoYes
CVE-2021-30596Chromium: CVE-2021-30596 Incorrect security UI in NavigationNoNoYes
CVE-2021-30594Chromium: CVE-2021-30594 Use after free in Page Info UINoNoYes
CVE-2021-30593Chromium: CVE-2021-30593 Out of bounds read in Tab StripNoNoYes
CVE-2021-30592Chromium: CVE-2021-30592 Out of bounds write in Tab GroupsNoNoYes
CVE-2021-30591Chromium: CVE-2021-30591 Use after free in File System APINoNoYes
CVE-2021-30590Chromium: CVE-2021-30590 Heap buffer overflow in BookmarksNoNoYes

Developer Tools Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-34532ASP.NET Core and Visual Studio Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-34485.NET Core and Visual Studio Information Disclosure VulnerabilityNoNo5Yes
CVE-2021-26423.NET Core and Visual Studio Denial of Service VulnerabilityNoNo7.5No

Microsoft Dynamics Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-36946Microsoft Dynamics Business Central Cross-site Scripting VulnerabilityNoNo5.4No
CVE-2021-34524Microsoft Dynamics 365 (on-premises) Remote Code Execution VulnerabilityNoNo8.1No
CVE-2021-36950Microsoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityNoNo5.4No

Microsoft Office Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-36941Microsoft Word Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-36940Microsoft SharePoint Server Spoofing VulnerabilityNoNo7.6No
CVE-2021-34478Microsoft Office Remote Code Execution VulnerabilityNoNo7.8Yes

System Center Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-34471Microsoft Windows Defender Elevation of Privilege VulnerabilityNoNo7.8Yes

Windows Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-26426Windows User Account Profile Picture Elevation of Privilege VulnerabilityNoNo7No
CVE-2021-36948Windows Update Medic Service Elevation of Privilege VulnerabilityYesNo7.8No
CVE-2021-26432Windows Services for NFS ONCRPC XDR Driver Remote Code Execution VulnerabilityNoNo9.8No
CVE-2021-26433Windows Services for NFS ONCRPC XDR Driver Information Disclosure VulnerabilityNoNo7.5Yes
CVE-2021-36926Windows Services for NFS ONCRPC XDR Driver Information Disclosure VulnerabilityNoNo7.5Yes
CVE-2021-36932Windows Services for NFS ONCRPC XDR Driver Information Disclosure VulnerabilityNoNo7.5Yes
CVE-2021-36933Windows Services for NFS ONCRPC XDR Driver Information Disclosure VulnerabilityNoNo7.5Yes
CVE-2021-26431Windows Recovery Environment Agent Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-34534Windows MSHTML Platform Remote Code Execution VulnerabilityNoNo6.8Yes
CVE-2021-34530Windows Graphics Component Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-34486Windows Event Tracing Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-34487Windows Event Tracing Elevation of Privilege VulnerabilityNoNo7No
CVE-2021-36938Windows Cryptographic Primitives Library Information Disclosure VulnerabilityNoNo5.5No
CVE-2021-36945Windows 10 Update Assistant Elevation of Privilege VulnerabilityNoNo7.3No
CVE-2021-34536Storage Spaces Controller Elevation of Privilege VulnerabilityNoNo7.8No

Windows ESU Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-34484Windows User Profile Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-26424Windows TCP/IP Remote Code Execution VulnerabilityNoNo9.9Yes
CVE-2021-36936Windows Print Spooler Remote Code Execution VulnerabilityNoYes8.8No
CVE-2021-36947Windows Print Spooler Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-34483Windows Print Spooler Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-36937Windows Media MPEG-4 Video Decoder Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-36942Windows LSA Spoofing VulnerabilityNoYes7.5Yes
CVE-2021-34533Windows Graphics Component Font Parsing Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-26425Windows Event Tracing Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-36927Windows Digital TV Tuner device registration application Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-34537Windows Bluetooth Driver Elevation of Privilege VulnerabilityNoNo7.8Yes
CVE-2021-34480Scripting Engine Memory Corruption VulnerabilityNoNo6.8Yes
CVE-2021-34535Remote Desktop Client Remote Code Execution VulnerabilityNoNo8.8Yes

Related blog posts