—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
===========================================================================
AUSCERT Security Bulletin
ASB-2021.0135
Microsoft Patch Tuesday update for Microsoft Extended
Security Update (ESU) for July 2021
14 July 2021
===========================================================================
AusCERT Security Bulletin Summary
———————————
Product: Windows 7
Windows Server 2008
Windows Server 2008 R2
Operating System: Windows
Impact/Access: Execute Arbitrary Code/Commands — Remote with User Interaction
Increased Privileges — Existing Account
Denial of Service — Remote/Unauthenticated
Access Confidential Data — Remote/Unauthenticated
Provide Misleading Information — Remote with User Interaction
Unauthorised Access — Remote with User Interaction
Resolution: Patch/Upgrade
CVE Names: CVE-2021-34516 CVE-2021-34514 CVE-2021-34511
CVE-2021-34507 CVE-2021-34504 CVE-2021-34500
CVE-2021-34499 CVE-2021-34498 CVE-2021-34497
CVE-2021-34496 CVE-2021-34494 CVE-2021-34492
CVE-2021-34476 CVE-2021-34457 CVE-2021-34456
CVE-2021-34448 CVE-2021-34447 CVE-2021-34446
CVE-2021-34444 CVE-2021-34442 CVE-2021-34441
CVE-2021-34440 CVE-2021-33788 CVE-2021-33786
CVE-2021-33783 CVE-2021-33782 CVE-2021-33780
CVE-2021-33765 CVE-2021-33764 CVE-2021-33757
CVE-2021-33756 CVE-2021-33754 CVE-2021-33752
CVE-2021-33750 CVE-2021-33749 CVE-2021-33746
CVE-2021-33745 CVE-2021-31979 CVE-2021-31183
Reference: ASB-2021.0134
OVERVIEW
Microsoft has released its monthly security patch update for the
month of July 2021.
This update resolves 39 vulnerabilities across the following
products: [1]
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
IMPACT
Microsoft has given the following details regarding these vulnerabilities.
Details Impact Severity
CVE-2021-31183 Denial of Service Important
CVE-2021-31979 Elevation of Privilege Important
CVE-2021-33745 Denial of Service Important
CVE-2021-33746 Remote Code Execution Important
CVE-2021-33749 Remote Code Execution Important
CVE-2021-33750 Remote Code Execution Important
CVE-2021-33752 Remote Code Execution Important
CVE-2021-33754 Remote Code Execution Important
CVE-2021-33756 Remote Code Execution Important
CVE-2021-33757 Security Feature Bypass Important
CVE-2021-33764 Information Disclosure Important
CVE-2021-33765 Spoofing Important
CVE-2021-33780 Remote Code Execution Important
CVE-2021-33782 Spoofing Important
CVE-2021-33783 Information Disclosure Important
CVE-2021-33786 Security Feature Bypass Important
CVE-2021-33788 Denial of Service Important
CVE-2021-34440 Information Disclosure Important
CVE-2021-34441 Remote Code Execution Important
CVE-2021-34442 Denial of Service Important
CVE-2021-34444 Denial of Service Important
CVE-2021-34446 Security Feature Bypass Important
CVE-2021-34447 Remote Code Execution Important
CVE-2021-34448 Remote Code Execution Critical
CVE-2021-34456 Elevation of Privilege Important
CVE-2021-34457 Information Disclosure Important
CVE-2021-34476 Denial of Service Important
CVE-2021-34492 Spoofing Important
CVE-2021-34494 Remote Code Execution Critical
CVE-2021-34496 Information Disclosure Important
CVE-2021-34497 Remote Code Execution Critical
CVE-2021-34498 Elevation of Privilege Important
CVE-2021-34499 Denial of Service Important
CVE-2021-34500 Information Disclosure Important
CVE-2021-34504 Remote Code Execution Important
CVE-2021-34507 Information Disclosure Important
CVE-2021-34511 Elevation of Privilege Important
CVE-2021-34514 Elevation of Privilege Important
CVE-2021-34516 Elevation of Privilege Important
MITIGATION
Microsoft recommends updating the software with the version made
available on the Microsoft Update Catalogue for the following
Knowledge Base articles. [1].
KB5004233, KB5004289, KB5004299, KB5004305, KB5004307
REFERENCES
[1] Microsoft Security Update Guidance
https://portal.msrc.microsoft.com/en-us/security-guidance
AusCERT has made every effort to ensure that the information contained
in this document is accurate. However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation’s site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.
===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072
Internet Email: auscert@auscert.org.au
Facsimile: (07) 3365 7031
Telephone: (07) 3365 4417 (International: +61 7 3365 4417)
AusCERT personnel answer during Queensland business hours
which are GMT+10:00 (AEST).
On call after hours for member emergencies only.
===========================================================================
—–BEGIN PGP SIGNATURE—–
Comment: http://www.auscert.org.au/render.html?it=1967
iQIVAwUBYO5hWuNLKJtyKPYoAQjBGw//VKASobBemWbwne4Szywy84S1XdQrcFS0
vxJP5mL/x4mTPBSFvvHqFQwQlPPUqSh6qhMxDI1ien8ZKPqRIEZRjQ2i8dHSg5ug
XMpLTKYGzL0aKIkpe32RKLQ0kkaqGXlmo/bkZm9ObcPzPqYwkhzm9X6DgbRp89yT
SWJY2NsKPv32gRtY/f44oufnojQLtfGZJA6RBA7RCAJTr3F2Jocz/JZ5iqZKgUSU
UQO5MdhSFozjkqmyS3qWkaL+kWryRdrQ4EDCAT49kXjyVbc0l8zNjsF5/MlrKTRY
IsDzPeUnHYhdGhE8SEW4uWOGT1p5Ijc0EXZK0FUpHmW2rs9wZRK6tT2q9+AVwxLe
CnL2+YrteVsvoN8cfJ27c9acnrvEPm0jH3XsRyhBMC1cWiq/jR1VH1i++waHY3ys
pB/OdMqswQuTZOqoDCKiunGdY6K77hc9qisFYxpkZ3ylpgA3brf2RSdoT+dRqYLk
5mvKbLxzqvczbD536ppuD740o1y8AyXCKzsQTF1qcLDP0rFkmThBmJmaJ/J5buSR
TcX88QrOR5qz5VMS84dzwkD0+frLbwimmUUE3erX2KzCp+r0iGdDD8u654f2sCnW
GYnZJjBwz3kIL/3Y6Y6snLqPGusOLLw7SIJhOSY+zUHt2LZahuTAHWXGrsZchNyp
IEaNHRS+dt0=
=WiIc
—–END PGP SIGNATURE—–
The post ASB-2021.0135 – ALERT [Win] Microsoft Extended Security Update products: Multiple vulnerabilities appeared first on Malware Devil.
https://malwaredevil.com/2021/07/14/asb-2021-0135-alert-win-microsoft-extended-security-update-products-multiple-vulnerabilities/?utm_source=rss&utm_medium=rss&utm_campaign=asb-2021-0135-alert-win-microsoft-extended-security-update-products-multiple-vulnerabilities
No comments:
Post a Comment