Detection and Response

Patch Tuesday - October 2021

|Last updated on Oct 12, 2021|1 min read
LinkedInFacebookX
Patch Tuesday - October 2021

Today’s Patch Tuesday sees Microsoft issuing fixes for over 70 CVEs, affecting the usual mix of their product lines. From Windows, Edge, and Office, to Exchange, SharePoint, and Dynamics, there is plenty of patching to do for workstation and server administrators alike.

One vulnerability has already been seen exploited in the wild: CVE-2021-40449 is an elevation of privilege vulnerability in all supported versions of Windows, including the newly released Windows 11. Rated as Important, this is likely being used alongside Remote Code Execution (RCE) and/or social engineering attacks to gain more complete control of targeted systems.

Three CVEs were publicly disclosed before today, though haven’t yet been observed in active exploitation. CVE-2021-40469 is an RCE vulnerability affecting Microsoft DNS servers, CVE-2021-41335 is another privilege escalation vulnerability in the Windows Kernel, and CVE-2021-41338 is a flaw in Windows AppContainer allowing attackers to bypass firewall rules.

Attackers will likely be paying attention to the latest Windows Print Spooler vulnerability – CVE-2021-36970 is a Spoofing vulnerability with a CVSSv3 score of 8.8 that we don’t yet have much more information about. Also worth noting is CVE-2021-40486, an RCE affecting Microsoft Word, OWA, as well as SharePoint Server, which can be exploited via the Preview Pane. CVE-2021-40487 is another RCE affecting SharePoint Server that Microsoft expects to be exploited before too long.

Another notable vulnerability is CVE-2021-26427, the latest in Exchange Server RCEs. The severity is mitigated by the fact that attacks are limited to a “logically adjacent topology,” meaning that it cannot be exploited directly over the public Internet. Three other vulnerabilities related to Exchange Server were also patched: CVE-2021-41350, a Spoofing vulnerability; CVE-2021-41348, allowing elevation of privilege; and CVE-2021-34453, which is a Denial of Service vulnerability.

Finally, virtualization administrators should be aware of two RCEs affecting Windows Hyper-V: CVE-2021-40461 and CVE-2021-38672. Both affect relatively new versions of Windows and are considered Critical, allowing a VM to escape from guest to host by triggering a memory allocation error, allowing it to read kernel memory in the host.

Summary Charts

2021-10-vuln_count_severity.png2021-10-cvssv3_hist.png2021-10-vuln_count_impact.png2021-10-vuln_count_component.png

Summary Tables

Apps Vulnerabilities

CVETitleExploitedPublicly Disclosed?CVSSv3 Base Scorehas FAQ?
CVE-2021-41363Intune Management Extension Security Feature Bypass VulnerabilityNoNo4.2Yes

Browser Vulnerabilities

CVETitleExploitedPublicly Disclosed?CVSSv3 Base Scorehas FAQ?
CVE-2021-37980Chromium: CVE-2021-37980 Inappropriate implementation in SandboxNoNoN/AYes
CVE-2021-37979Chromium: CVE-2021-37979 Heap buffer overflow in WebRTCNoNoN/AYes
CVE-2021-37978Chromium: CVE-2021-37978 Heap buffer overflow in BlinkNoNoN/AYes
CVE-2021-37977Chromium: CVE-2021-37977 Use after free in Garbage CollectionNoNoN/AYes
CVE-2021-37976Chromium: CVE-2021-37976 Information leak in coreNoNoN/AYes
CVE-2021-37975Chromium: CVE-2021-37975 Use after free in V8NoNoN/AYes
CVE-2021-37974Chromium: CVE-2021-37974 Use after free in Safe BrowsingNoNoN/AYes

Developer Tools Vulnerabilities

CVETitleExploitedPublicly Disclosed?CVSSv3 Base Scorehas FAQ?
CVE-2021-3450OpenSSL: CVE-2021-3450 CA certificate check bypass with X509_V_FLAG_X509_STRICTNoNoN/AYes
CVE-2021-3449OpenSSL: CVE-2021-3449 NULL pointer deref in signature_algorithms processingNoNoN/AYes
CVE-2020-1971OpenSSL: CVE-2020-1971 EDIPARTYNAME NULL pointer de-referenceNoNoN/AYes
CVE-2021-41355.NET Core and Visual Studio Information Disclosure VulnerabilityNoNo5.7Yes

ESU Windows Vulnerabilities

CVETitleExploitedPublicly Disclosed?CVSSv3 Base Scorehas FAQ?
CVE-2021-38663Windows exFAT File System Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-40465Windows Text Shaping Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-36953Windows TCP/IP Denial of Service VulnerabilityNoNo7.5No
CVE-2021-40460Windows Remote Procedure Call Runtime Security Feature Bypass VulnerabilityNoNo6.5Yes
CVE-2021-36970Windows Print Spooler Spoofing VulnerabilityNoNo8.8No
CVE-2021-41332Windows Print Spooler Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2021-41331Windows Media Audio Decoder Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-41342Windows MSHTML Platform Remote Code Execution VulnerabilityNoNo6.8Yes
CVE-2021-41335Windows Kernel Elevation of Privilege VulnerabilityNoYes7.8No
CVE-2021-40455Windows Installer Spoofing VulnerabilityNoNo5.5No
CVE-2021-26442Windows HTTP.sys Elevation of Privilege VulnerabilityNoNo7No
CVE-2021-41340Windows Graphics Component Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-38662Windows Fast FAT File System Driver Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-41343Windows Fast FAT File System Driver Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-40469Windows DNS Server Remote Code Execution VulnerabilityNoYes7.2Yes
CVE-2021-40443Windows Common Log File System Driver Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-40466Windows Common Log File System Driver Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-40467Windows Common Log File System Driver Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-40449Win32k Elevation of Privilege VulnerabilityYesNo7.8No
CVE-2021-40489Storage Spaces Controller Elevation of Privilege VulnerabilityNoNo7.8Yes

Exchange Server Vulnerabilities

CVETitleExploitedPublicly Disclosed?CVSSv3 Base Scorehas FAQ?
CVE-2021-41350Microsoft Exchange Server Spoofing VulnerabilityNoNo6.5No
CVE-2021-26427Microsoft Exchange Server Remote Code Execution VulnerabilityNoNo9Yes
CVE-2021-41348Microsoft Exchange Server Elevation of Privilege VulnerabilityNoNo8No
CVE-2021-34453Microsoft Exchange Server Denial of Service VulnerabilityNoNo7.5No

Microsoft Dynamics Vulnerabilities

CVETitleExploitedPublicly Disclosed?CVSSv3 Base Scorehas FAQ?
CVE-2021-40457Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting VulnerabilityNoNo7.4Yes
CVE-2021-41353Microsoft Dynamics 365 (on-premises) Spoofing VulnerabilityNoNo5.4No
CVE-2021-41354Microsoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityNoNo4.1No

Microsoft Office Vulnerabilities

CVETitleExploitedPublicly Disclosed?CVSSv3 Base Scorehas FAQ?
CVE-2021-40486Microsoft Word Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-40484Microsoft SharePoint Server Spoofing VulnerabilityNoNo7.6No
CVE-2021-40483Microsoft SharePoint Server Spoofing VulnerabilityNoNo7.6No
CVE-2021-41344Microsoft SharePoint Server Remote Code Execution VulnerabilityNoNo8.1No
CVE-2021-40487Microsoft SharePoint Server Remote Code Execution VulnerabilityNoNo8.1Yes
CVE-2021-40482Microsoft SharePoint Server Information Disclosure VulnerabilityNoNo5.3Yes
CVE-2021-40480Microsoft Office Visio Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-40481Microsoft Office Visio Remote Code Execution VulnerabilityNoNo7.1Yes
CVE-2021-40471Microsoft Excel Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-40473Microsoft Excel Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-40474Microsoft Excel Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-40479Microsoft Excel Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-40485Microsoft Excel Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-40472Microsoft Excel Information Disclosure VulnerabilityNoNo5.5Yes

Microsoft Office Windows Vulnerabilities

CVETitleExploitedPublicly Disclosed?CVSSv3 Base Scorehas FAQ?
CVE-2021-40454Rich Text Edit Control Information Disclosure VulnerabilityNoNo5.5Yes

System Center Vulnerabilities

CVETitleExploitedPublicly Disclosed?CVSSv3 Base Scorehas FAQ?
CVE-2021-41352SCOM Information Disclosure VulnerabilityNoNo7.5Yes

Windows Vulnerabilities

CVETitleExploitedPublicly Disclosed?CVSSv3 Base Scorehas FAQ?
CVE-2021-40464Windows Nearby Sharing Elevation of Privilege VulnerabilityNoNo8No
CVE-2021-40463Windows NAT Denial of Service VulnerabilityNoNo7.7No
CVE-2021-40462Windows Media Foundation Dolby Digital Atmos Decoders Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-41336Windows Kernel Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-38672Windows Hyper-V Remote Code Execution VulnerabilityNoNo8Yes
CVE-2021-40461Windows Hyper-V Remote Code Execution VulnerabilityNoNo8No
CVE-2021-40477Windows Event Tracing Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-41334Windows Desktop Bridge Elevation of Privilege VulnerabilityNoNo7No
CVE-2021-40475Windows Cloud Files Mini Filter Driver Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-40468Windows Bind Filter Driver Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-41347Windows AppX Deployment Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-41338Windows AppContainer Firewall Rules Security Feature Bypass VulnerabilityNoYes5.5No
CVE-2021-40476Windows AppContainer Elevation Of Privilege VulnerabilityNoNo7.5No
CVE-2021-40456Windows AD FS Security Feature Bypass VulnerabilityNoNo5.3Yes
CVE-2021-40450Win32k Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-41357Win32k Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-40478Storage Spaces Controller Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-40488Storage Spaces Controller Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-26441Storage Spaces Controller Elevation of Privilege VulnerabilityNoNo7.8Yes
CVE-2021-41345Storage Spaces Controller Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-41330Microsoft Windows Media Foundation Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-41339Microsoft DWM Core Library Elevation of Privilege VulnerabilityNoNo4.7No
CVE-2021-40470DirectX Graphics Kernel Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-41346Console Window Host Security Feature Bypass VulnerabilityNoNo5.3No
CVE-2021-41337Active Directory Security Feature Bypass VulnerabilityNoNo4.9Yes
CVE-2021-41361Active Directory Federation Server Spoofing VulnerabilityNoNo5.4Yes

Related blog posts