Welcome to our

Cyber Security News Aggregator

.

Cyber Tzar

provide a

cyber security risk management

platform; including automated penetration tests and risk assesments culminating in a "cyber risk score" out of 1,000, just like a credit score.

Microsoft fixes 50 vulnerabilities for June, but patch first the six exploited in the wild

published on 2021-06-09 21:12:56 UTC by Steve Zurier
Content:
For June’s Patch Tuesday yesterday Microsoft fixed 50 vulnerabilities, six of which are being actively exploited in the wild. (Photo by Kevork Djansezian/Getty Images)

For June’s Patch Tuesday yesterday Microsoft fixed 50 vulnerabilities, six of which are being actively exploited in the wild.

While security researchers say that administrators should focus on all these patches as soon as possible, security teams can start by focusing on the six currently exploited.

Allan Liska of Recorded Future’s computer security incident response team, lists out the reasons why security teams should take the six exploited vulnerabilities seriously:

  • CVE-2021-33742:  A remote code execution (RCE) vulnerability in the Windows MSHTML Platform. It’s a critical vulnerability that affects Windows 7 through 10 and Windows Server 2008 and 2012.
  • CVE-2021-31955: An information disclosure vulnerability in the Windows Kernel. Microsoft rates this vulnerability as Important and it affects Windows 10 and Windows Server 2019. Microsoft rates exploitation of this vulnerability as low complexity and because it’s being exploited in the wild already, can be quicklyu picked up on by other threat actors.
  • CVE-2021-31201, CVE-2021-31199, CVE-2021-33739, CVE-2021-31956: These are all  “elevation of privilege” vulnerabilities rated Important by Microsoft. Elevation of privilege vulnerabilities are important because attackers like to chain these vulnerabilities with RCE vulnerabilities (such as CVE-2021-33742) as part of their attacks. The attackers use the RCE vulnerability to gain initial access, then the elevation of privilege vulnerabilities to gain administrative access on the compromised system.

The post Microsoft fixes 50 vulnerabilities for June, but patch first the six exploited in the wild appeared first on SC Media.

Article: Microsoft fixes 50 vulnerabilities for June, but patch first the six exploited in the wild - published over 3 years ago.

https://www.scmagazine.com/home/security-news/vulnerabilities/microsoft-fixes-50-vulnerabilities-for-june-but-patch-first-the-six-exploited-in-the-wild/   
Published: 2021 06 09 21:12:56
Received: 2021 06 09 22:00:41
Feed: SC Magazine
Source: SC Media
Category: News
Topic: Cyber Security
Views: 1

Custom HTML Block

Click to Open Code Editor