Linchakin

Microsoft Patch Tuesday fixes actively exploited zero‑day and 85 other flaws

 September 15, 2021     No comments   

The most recent Patch Tuesday includes a fix for the previously disclosed and actively exploited remote code execution flaw in MSHTML.

The arrival of the second Tuesday of the month can only mean one thing in cybersecurity terms, Microsoft is rolling out patches for security vulnerabilities in Windows and its other offerings. This time round Microsoft’s Patch Tuesday brings fixes to no fewer than 86 security loopholes including one that has been both previously disclosed and actively exploited in the wild. Of the grand total, three security flaws received the highest severity rating of “critical”.

Indexed as CVE-2021-40444, the remote code execution vulnerability holding a rating of ‘critical’ on the CVSS scale, resides in MSHTML, a browser engine for Internet Explorer also commonly referred to as Trident. While Microsoft did release an advisory regarding the actively exploited zero-day it didn’t provide an out-of-band update and rather opted to fix it as part of this month’s batch of security updates.

“An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights,” Microsoft said describing how an attacker could exploit the vulnerability.

Another critical vulnerability that merits mentioning resides in Open Management Infrastructure (OMI), an open-source project which aims to improve Web-Based Enterprise Management standards. Tracked as CVE-2021-38647 the remote code execution vulnerability earned an ‘almost perfect score’ of 9.8 out of 10 on the CVSS scale. According to the Redmond tech titan, an attacker could exploit the security loophole by sending a specially crafted message through HTTPS to a port listening to OMI on a susceptible system.

Closing up the trio of security flaws with a classification of critical is yet another remote code execution bug. Indexed as CVE-2021-36965, the vulnerability resides in the Windows WLAN AutoConfig Service component, which is responsible for automatically connecting to wireless networks.

Security updates have been released for a wide range of products, including Microsoft Office, Edge, SharePoint, as well as other products in Microsoft’s portfolio.

All updates are available via this Microsoft Update Catalog for all supported versions of Windows. Both regular users and system administrators would be well advised to apply the patches as soon as practicable.

Adblock test (Why?)


You may be interested in:
>> Is a Chromebook worth replacing a Windows laptop?
>> Find out in detail the outstanding features of Google Pixel 4a
>> Top 7 best earbuds you should not miss

Related Posts:
>> Recognizing 12 Basic Body Shapes To Choose Better Clothes
>>Ranking the 10 most used smart technology devices
>> Top 5+ Best E-readers: Compact & Convenient Pen
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook

Related Posts:

  • BruteShark - Network Analysis Tool BruteShark is a Network Forensic Analysis Tool (NFAT) that performs deep processing and inspection of network traffic (mainly PCAP files, but it also… Read More
  • You Can Be a Coding Hero Too: Do Not Fear TryingProgramming is one of the most demanded skills in today's world. In the future, it'll play an even bigger role since digitalization is in full swing. … Read More
  • The #Blockchain Writing Contest Hey Hackers! We are bringing another writing contest for our fantastic community! Welcome to the #Blockchain Writing Contest hosted by Hack… Read More
  • Virtual networks need a rethink to meet hybrid-, multi-cloud demands Everyone in tech likely thinks they know what “cloud computing” and “networking” mean, but they’re probably wrong, and their misconceptions about the… Read More
  • FCC looks into BGP vulnerabilities in light of Russian hacking threat The FCC is launching an inquiry into security issues surrounding the Border Gateway Protocol (BGP), a widely used standard used to manage interconnec… Read More
Newer Post Older Post Home

0 Comments:

Post a Comment


Copyright © 2025 Linchakin | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates