Patch Tuesday - December 2021

 

Description

Patch Tuesday - December 2021

This month’s Patch Tuesday comes in the middle of a global effort to mitigate Apache Log4j CVE-2021-44228. In today’s security release, Microsoft issued fixes for 83 vulnerabilities across an array of products — including a fix for Windows Defender for IoT, which is vulnerable to CVE-2021-44228 amongst seven other remote code execution (RCE) vulnerabilities (the cloud service is not affected). Six CVEs in the bulletin have been publicly disclosed; the only vulnerability noted as being exploited in the wild in this month’s release is CVE-2021-43890, a Windows AppX Installer spoofing bug that may aid in social engineering attacks and has evidently been used in Emotet malware campaigns.

Interestingly, this round of fixes also includes CVE-2021-43883, a Windows Installer privilege escalation bug whose advisory is sparse despite the fact that it appears to affect all supported versions of Windows. While there’s no indication in the advisory that the two vulnerabilities are related, CVE-2021-43883 looks an awful lot like the fix for a zero-day vulnerability that made a splash in the security community last month after proof-of-concept exploit code was released and in-the-wild attacks began. The zero-day vulnerability, which researchers hypothesized was a patch bypass for CVE-2021-41379, allowed low-privileged attackers to overwrite protected files and escalate to SYSTEM. Rapid7’s vulnerability research team did a full root cause analysis of the bug as attacks ramped up in November.

As usual, RCE flaws figure prominently in the “Critical”-rated CVEs this month. In addition to Windows Defender for IoT, critical RCE bugs were fixed this month in Microsoft Office, Microsoft Devices, Internet Storage Name Service (iSNS), and the WSL extension for Visual Studio Code. Given the outsized risk presented by most vulnerable implementations of Log4Shell, administrators should prioritize patches for any products affected by CVE-2021-44228. Past that, put critical server-side and OS RCE patches at the top of your list, and we’d advise sneaking in the fix for CVE-2021-43883 despite its lower severity rating.

Summary charts

Patch Tuesday - December 2021Patch Tuesday - December 2021Patch Tuesday - December 2021Patch Tuesday - December 2021

Summary tables

Apps Vulnerabilities

CVEVulnerability TitleExploitedPublicly Disclosed?CVSSv3Has FAQ?
CVE-2021-43890Windows AppX Installer Spoofing VulnerabilityYesYes7.1Yes
CVE-2021-43905Microsoft Office app Remote Code Execution VulnerabilityNoNo9.6Yes

Browser Vulnerabilities

CVEVulnerability TitleExploitedPublicly Disclosed?CVSSv3Has FAQ?
CVE-2021-4068Chromium: CVE-2021-4068 Insufficient validation of untrusted input in new tab pageNoNoN/AYes
CVE-2021-4067Chromium: CVE-2021-4067 Use after free in window managerNoNoN/AYes
CVE-2021-4066Chromium: CVE-2021-4066 Integer underflow in ANGLENoNoN/AYes
CVE-2021-4065Chromium: CVE-2021-4065 Use after free in autofillNoNoN/AYes
CVE-2021-4064Chromium: CVE-2021-4064 Use after free in screen captureNoNoN/AYes
CVE-2021-4063Chromium: CVE-2021-4063 Use after free in developer toolsNoNoN/AYes
CVE-2021-4062Chromium: CVE-2021-4062 Heap buffer overflow in BFCacheNoNoN/AYes
CVE-2021-4061Chromium: CVE-2021-4061 Type Confusion in V8NoNoN/AYes
CVE-2021-4059Chromium: CVE-2021-4059 Insufficient data validation in loaderNoNoN/AYes
CVE-2021-4058Chromium: CVE-2021-4058 Heap buffer overflow in ANGLENoNoN/AYes
CVE-2021-4057Chromium: CVE-2021-4057 Use after free in file APINoNoN/AYes
CVE-2021-4056Chromium: CVE-2021-4056: Type Confusion in loaderNoNoN/AYes
CVE-2021-4055Chromium: CVE-2021-4055 Heap buffer overflow in extensionsNoNoN/AYes
CVE-2021-4054Chromium: CVE-2021-4054 Incorrect security UI in autofillNoNoN/AYes
CVE-2021-4053Chromium: CVE-2021-4053 Use after free in UINoNoN/AYes
CVE-2021-4052Chromium: CVE-2021-4052 Use after free in web appsNoNoN/AYes

Developer Tools Vulnerabilities

CVEVulnerability TitleExploitedPublicly Disclosed?CVSSv3Has FAQ?
CVE-2021-43907Visual Studio Code WSL Extension Remote Code Execution VulnerabilityNoNo9.8No
CVE-2021-43908Visual Studio Code Spoofing VulnerabilityNoNonanNo
CVE-2021-43891Visual Studio Code Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-43896Microsoft PowerShell Spoofing VulnerabilityNoNo5.5No
CVE-2021-43892Microsoft BizTalk ESB Toolkit Spoofing VulnerabilityNoNo7.4No
CVE-2021-43225Bot Framework SDK Remote Code Execution VulnerabilityNoNo7.5No
CVE-2021-43877ASP.NET Core and Visual Studio Elevation of Privilege VulnerabilityNoNo7.8No

Device Vulnerabilities

CVEVulnerability TitleExploitedPublicly Disclosed?CVSSv3Has FAQ?
CVE-2021-43899Microsoft 4K Wireless Display Adapter Remote Code Execution VulnerabilityNoNo9.8Yes

Microsoft Office Vulnerabilities

CVEVulnerability TitleExploitedPublicly Disclosed?CVSSv3Has FAQ?
CVE-2021-42295Visual Basic for Applications Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-42320Microsoft SharePoint Server Spoofing VulnerabilityNoNo8Yes
CVE-2021-43242Microsoft SharePoint Server Spoofing VulnerabilityNoNo7.6No
CVE-2021-42309Microsoft SharePoint Server Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2021-42294Microsoft SharePoint Server Remote Code Execution VulnerabilityNoNo7.2Yes
CVE-2021-43255Microsoft Office Trust Center Spoofing VulnerabilityNoNo5.5Yes
CVE-2021-43875Microsoft Office Graphics Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-42293Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege VulnerabilityNoNo6.5Yes
CVE-2021-43256Microsoft Excel Remote Code Execution VulnerabilityNoNo7.8Yes

System Center Vulnerabilities

CVEVulnerability TitleExploitedPublicly Disclosed?CVSSv3Has FAQ?
CVE-2021-43882Microsoft Defender for IoT Remote Code Execution VulnerabilityNoNo9Yes
CVE-2021-42311Microsoft Defender for IoT Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2021-42313Microsoft Defender for IoT Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2021-42314Microsoft Defender for IoT Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2021-42315Microsoft Defender for IoT Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2021-41365Microsoft Defender for IoT Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2021-42310Microsoft Defender for IoT Remote Code Execution VulnerabilityNoNo8.1Yes
CVE-2021-43889Microsoft Defender for IoT Remote Code Execution VulnerabilityNoNo7.2Yes
CVE-2021-43888Microsoft Defender for IoT Information Disclosure VulnerabilityNoNo7.5Yes
CVE-2021-42312Microsoft Defender for IOT Elevation of Privilege VulnerabilityNoNo7.8Yes

Windows Vulnerabilities

CVEVulnerability TitleExploitedPublicly Disclosed?CVSSv3Has FAQ?
CVE-2021-43247Windows TCP/IP Driver Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-43237Windows Setup Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-43239Windows Recovery Environment Agent Elevation of Privilege VulnerabilityNoNo7.1No
CVE-2021-43231Windows NTFS Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-43880Windows Mobile Device Management Elevation of Privilege VulnerabilityNoYes5.5Yes
CVE-2021-43244Windows Kernel Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2021-43246Windows Hyper-V Denial of Service VulnerabilityNoNo5.6No
CVE-2021-43232Windows Event Tracing Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-43248Windows Digital Media Receiver Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-43214Web Media Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-43243VP9 Video Extensions Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-43228SymCrypt Denial of Service VulnerabilityNoNo7.5No
CVE-2021-43227Storage Spaces Controller Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-43235Storage Spaces Controller Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-43240NTFS Set Short Name Elevation of Privilege VulnerabilityNoYes7.8No
CVE-2021-40452HEVC Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-40453HEVC Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-41360HEVC Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-43219DirectX Graphics Kernel File Denial of Service VulnerabilityNoNo7.4No

Windows ESU Vulnerabilities

CVEVulnerability TitleExploitedPublicly Disclosed?CVSSv3Has FAQ?
CVE-2021-43215iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code ExecutionNoNo9.8Yes
CVE-2021-43238Windows Remote Access Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-43223Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-41333Windows Print Spooler Elevation of Privilege VulnerabilityNoYes7.8No
CVE-2021-43229Windows NTFS Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-43230Windows NTFS Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-40441Windows Media Center Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-43883Windows Installer Elevation of Privilege VulnerabilityNoYes7.8No
CVE-2021-43234Windows Fax Service Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-43217Windows Encrypting File System (EFS) Remote Code Execution VulnerabilityNoNo8.1Yes
CVE-2021-43893Windows Encrypting File System (EFS) Elevation of Privilege VulnerabilityNoYes7.5No
CVE-2021-43245Windows Digital TV Tuner Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-43224Windows Common Log File System Driver Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-43226Windows Common Log File System Driver Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-43207Windows Common Log File System Driver Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-43233Remote Desktop Client Remote Code Execution VulnerabilityNoNo7.5No
CVE-2021-43222Microsoft Message Queuing Information Disclosure VulnerabilityNoNo7.5Yes
CVE-2021-43236Microsoft Message Queuing Information Disclosure VulnerabilityNoNo7.5Yes
CVE-2021-43216Microsoft Local Security Authority Server (lsasrv) Information Disclosure VulnerabilityNoNo6.5Yes

Post a Comment

Previous Post Next Post