Saturday, June 3, 2023
News 21 AV
  • Home
  • Tech News
    Ban predictive policing systems in EU AI Act, says civil society

    Insights on Nordic artificial intelligence strategies

    Unionised contract workers who train Google’s AI win pay rise

    Unionised contract workers who train Google’s AI win pay rise

    Government given until autumn 2023 to create technology roadmap to support net-zero strategy

    Government given until autumn 2023 to create technology roadmap to support net-zero strategy

    Ellison-founded sailing league SailGP plumps for Oracle NetSuite to expand

    Ellison-founded sailing league SailGP plumps for Oracle NetSuite to expand

    Cabinet Office looks to expand public data sharing for digital ID

    Cabinet Office looks to expand public data sharing for digital ID

    A pandemic retail trend that’s here to stay?

    LockBit cartel suspected of Royal Mail cyber attack

    Umbrella firm Parasol confirms ‘malicious activity’ as root cause of ongoing systems outage

    Government accused of leaving umbrella company regulation in limbo by shelving enforcement body

    UK government completes trials of age estimation technology

    UK government completes trials of age estimation technology

    Cyber insurance: The good, the bad and the ugly

    Companies warned to step up cyber security to become ‘insurable’

  • Virtual reality
    The other DWI: Driving while immersed

    The other DWI: Driving while immersed

    We tried out Canon's VR calling app Kokomo

    We tried out Canon’s VR calling app Kokomo

    Peacock subscribers can now stream content on Meta Quest devices

    Peacock subscribers can now stream content on Meta Quest devices

    A decade later, this VR treadmill is finally ready to ship

    A decade later, this VR treadmill is finally ready to ship

    How XR Technologies Are Making Design Reviews Immersive | NVIDIA Blog

    How XR Technologies Are Making Design Reviews Immersive | NVIDIA Blog

    Review: PlayStation VR2 is a huge leap that still can't escape its niche

    Review: PlayStation VR2 is a huge leap that still can’t escape its niche

    Meta Quest users can now tap and swipe in VR without controllers

    Meta Quest users can now tap and swipe in VR without controllers

    Former Salesforce exec Bret Taylor is teaming up with Google AR/VR vet Clay Bavor on mystery startup

    Former Salesforce exec Bret Taylor is teaming up with Google AR/VR vet Clay Bavor on mystery startup

    Google’s GV backs SideQuest, an unofficial Meta Quest app store

    Meta’s Reality Labs lost $13.7 billion on VR and AR last year

  • Lifestyle
    JUNTOSO 3 Pieces Recliner Sofa Sets

    How To Choose The Right Velvet Chesterfield Sofa For Your Living Room

    High-End Strollers

    Luxury Redefined: 6 Most Innovative Features in High-End Strollers

    Tips for Caregivers and Inter-abled Partners

    Top Tips for Choosing the Best Senior Living Facilities for You or Your Loved Ones

    Pros and Cons of No-Fault Insurance

    What are Medigap Plans? – Morning Lazziness

    Organizer1

    Organize Your Workspace With Industrial Storage Systems

    coffee

    Caffeine and Beyond: Natural Energy-Boosting Alternatives to Fight Fatigue

    How to Save Money as an Expat

    Staying out of Debt While Living With a Chronic Illness

    CapCut Online Editor

    Powerful Product Demos: Utilizing CapCut Online Editor for Your Business

    hair serum woman

    How To Use Redensyl Hair Growth Serum

  • Beauty
    Water Flosser

    This Bestselling Waterpik Is On Sale Right Now

    Proud To Be Pink Bobbi Brown Gloss Duo

    Proud To Be Pink Bobbi Brown Gloss Duo

    ColourPop x Snitchery Collection Swatches (Eyes & Cheeks)

    ColourPop x Snitchery Collection Swatches (Eyes & Cheeks)

    Image may contain Clothing Apparel Human Person Lingerie and Underwear

    Period Care Ads Are Woefully Lacking in Disability Representation

    mileys new years eve party

    Who Is Maxx Morando? – All About Miley Cyrus’s New Boyfriend

    Dior Cosmic Eyes (359) Eyeshadow Palette

    Dior Holiday 2022 Collection Swatches

    preview for How Emma Stone Became an Oscar-Winning Actress

    Who Is Dave McCary? Meet Emma Stone’s Husband and Baby Girl’s Dad

    Coloured Raine Sunset Chic Eyeshadow Palette Review & Swatches

    Coloured Raine Sunset Chic Eyeshadow Palette Review & Swatches

    Mila Kunis Criticizes Celebs Who Gave Will Smith a Standing Ovation at the Oscars After The Slap

    Mila Kunis Criticizes Celebs Who Gave Will Smith a Standing Ovation at the Oscars After The Slap

  • Health & Fitness
    2023 CrossFit North America West Semifinal Results — Alex Gazan, Patrick Vellner Notch Wins

    2023 CrossFit North America West Semifinal Results — Alex Gazan, Patrick Vellner Notch Wins

    Q&A With Ann Partridge, MD, MPH

    Are Psoriasis and Allergies Linked?

    Lucy Underdown Sets Kratos Bar Deadlift World Record of 305 Kilograms (672.4 Pounds)

    Lucy Underdown Sets Kratos Bar Deadlift World Record of 305 Kilograms (672.4 Pounds)

    Q&A With Ann Partridge, MD, MPH

    Can Statins Cause Brain Fog?

    The 10 Best Medicine Ball Exercises for Power, Conditioning, and More

    The 10 Best Medicine Ball Exercises for Power, Conditioning, and More

    WebMD: Better information. Better health.

    The Nuances of Treating Vitiligo in People of Color

    WebMD: Better information. Better health.

    Build a Care Team You Trust

    Hi-Tech Implant Helps Paralyzed Man Walk More Naturally

    Hi-Tech Implant Helps Paralyzed Man Walk More Naturally

    How to Do the Incline Dumbbell Bench Press for Upper Pec Muscle and Pressing Strength

    How to Do the Incline Dumbbell Bench Press for Upper Pec Muscle and Pressing Strength

  • Equipment
  • Login
No Result
View All Result
News 21 AV
Home Tech News

November Patch Tuesday drop fixes bugs in Excel, Exchange Server

News 21 AV by News 21 AV
November 11, 2021
in Tech News
0
November Patch Tuesday drop fixes bugs in Excel, Exchange Server
0
SHARES
1
VIEWS
FacebookTwitter


On another comparatively light Patch Tuesday, Microsoft has issued fixes for a total of 55 newly uncovered common vulnerabilities and exposures (CVEs), six of them rated as critical, and two that are already being publicly exploited.

Related posts

Ban predictive policing systems in EU AI Act, says civil society

Insights on Nordic artificial intelligence strategies

January 14, 2023
Unionised contract workers who train Google’s AI win pay rise

Unionised contract workers who train Google’s AI win pay rise

January 14, 2023

The two CVEs in question are CVE-2021-42292, a security feature bypass vulnerability in Microsoft Excel, and CVE-2021-42321, a remote code execution (RCE) vulnerability in Microsoft Exchange Server. Both are rated important, with CVSS scores of 7.8 and 8.8, respectively.

“CVE-2021-42321 should be of primary concern,” said Recorded Future senior security architect Allan Liska. “This vulnerability is one that is being actively exploited in the wild. Exchange vulnerabilities have been of particular concern this year.

“Both Chinese nation state actors and the cyber criminals behind the DearCry ransomware (also believed to be operating out of China) exploited earlier vulnerabilities in Microsoft Exchange (CVE-2021-26855 and CVE-2021-27065). While Microsoft only rates the vulnerability as ‘Important’ because an attacker has to be authenticated to exploit it, Recorded Future has noted that gaining legitimate credential access to Windows systems has become trivial for both nation state and cyber criminal actors. This should be prioritised for patching. 

“The other vulnerability that is being exploited in the wild is CVE-2021-42292. This is a security feature bypass vulnerability for Microsoft Excel for both Windows and MacOS computers. This vulnerability affects versions 2013-2021.”

Liska added: “Microsoft is not clear in its description which security feature is bypassed by the vulnerability. However, again, the fact that it is being exploited in the wild is concerning and means it should be prioritised for patching. Microsoft Excel is a frequent target of both nation state attackers and cyber criminals.”

The six critical vulnerabilities are listed as: CVE-2021-3711, which is a decryption buffer overflow flaw in OpenSSL; CVE-2021-26443, another RCE vulnerability in Microsoft Virtual Machine Bus; CVE-2021-38666, an RCE vulnerability in Remote Desktop Client; CVE-2021-42270, a memory corruption vulnerability in the Chakra scripting engine; CVE-2021-42298, an RCE vulnerability in Microsoft Defender; and CVE-2021-42316, yet another RCE vulnerability in Microsoft Dynamics 365.

None of the above-listed bugs are currently being exploited in the wild at the time of writing, although this may well change in short order, and many in the security community are already raising concerns, among them Danny Kim, principal architect at Virsec, who said the Microsoft Defender vulnerability was particularly worrying.

“With the exploitability assessment of ‘Exploitation more likely’ and the severity score and the repeatability of this attack, I think this CVE should be top of mind for all enterprises,” Kim told Computer Weekly in emailed comments.

“Windows Defender runs on all supported versions of Windows. This vulnerability significantly increases the potential attack surface for today’s organisations due to the popularity of Windows Defender. This CVE does require some user interaction, however we have seen in the past how attackers can use social engineering/phishing emails to achieve such interaction fairly easily.”

Jay Goodman of Automox flagged both the vulnerabilities in the Chakra scripting engine and Microsoft Dynamics 365 as noteworthy.

“The Chakra scripting engine is widely used in Microsoft Edge and RCE vulnerabilities are particularly sensitive given that they enable attackers to directly run malicious code on the exploited systems,” he said. “It is highly recommended that IT administrators remediate this vulnerability within 72 hours to minimise exposure to threat actors.

“Microsoft Dynamics 365 is a resource planning and CRM tool from Microsoft and this vulnerability is present in the 9.0 and 9.1 versions of their on-premise option. Remote code execution vulnerabilities are particularly sensitive given that they enable attackers to directly run malicious code on the exploited systems.”

Goodman added: “It is highly recommended that IT administrators remediate this vulnerability within 72 hours to minimise exposure to threat actors, especially in a tool with access to sensitive customer and business data like a CRM solution.”

Meanwhile, another lighter-than-usual Patch Tuesday has raised eyebrows at Trend Micro’s Zero Day Initiative, where communications lead Dustin Childs suggested that the downward trend might be a cause for concern.

“Historically speaking, 55 patches in November is a relatively low number,” he wrote. “Last year, there were more than double this number of CVEs fixed. Even going back to 2018, when there were only 691 CVEs fixed all year, there were more November CVEs fixed than in this month.

“Given that December is typically a slower month patch-wise, it causes one to wonder if there is a backlog of patches awaiting deployment due to various factors. It seems odd that Microsoft would be releasing fewer patches after seeing nothing but increases across the industry for years.”



Source link

Tags: bugsDropExcelExchangefixesNovemberPatchserverTuesday
Previous Post

Are Food and Fitness Enough to Fight Coronary Artery Disease?

Next Post

ColourPop Radioactive & Mineral Girl Creme Gel Liners Reviews & Swatches

Next Post
ColourPop Radioactive Crème Gel Colour

ColourPop Radioactive & Mineral Girl Creme Gel Liners Reviews & Swatches

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

CHANEL Chance Eau Tendre Scented Bath Tablets

CHANEL Chance Eau Tendre Scented Bath Tablets

12 months ago
10 Best Portable DVD Players for 2022

10 Best Portable DVD Players for 2022

1 year ago
Rhianon Lovelace Sets U64 Atlas Stone World Record of 146.8 Kilograms (324 Pounds)

Rhianon Lovelace Sets U64 Atlas Stone World Record of 146.8 Kilograms (324 Pounds)

3 months ago
Deck of Scarlet Solid Lip Oil New Shades

Deck of Scarlet Solid Lip Oil New Shades

12 months ago

BROWSE BY CATEGORIES

  • Beauty
  • Equipment
  • Health & Fitness
  • Lifestyle
  • Tech News
  • Virtual reality

BROWSE BY TOPICS

Beauty Equipment Health & Fitness Lifestyle Tech News Virtual reality

POPULAR NEWS

  • The 20 Best Leg Exercises for Size and Strength

    The 20 Best Leg Exercises for Size and Strength

    0 shares
    Share 0 Tweet 0
  • Who Is Dalton Gomez – Meet Ariana Grande’s Husband

    0 shares
    Share 0 Tweet 0
  • 14 Best Sanitary Napkins To Provide Comfort During Periods

    0 shares
    Share 0 Tweet 0
  • 10 Best CD Players in 2021

    0 shares
    Share 0 Tweet 0
  • Why Power Dressing is Important at Workplace For Women

    0 shares
    Share 0 Tweet 0
News 21 AV

We bring you the best of latest news articles with an emphasis. We offers an original take on the latest in Lifestyle, fashion, high tech and health & fitness informations and guides.

Follow us on social media:

Recent News

  • Anxiety, Your Brain, and Long COVID: What the Research Says
  • Black and Gray Decor Spiced With Hot Red Accents & Lush Terrariums
  • Blessing Awodibu Set to Compete in 2023 Chicago Pro 

Category

  • Beauty
  • Equipment
  • Health & Fitness
  • Lifestyle
  • Tech News
  • Virtual reality

Recent News

2023 CrossFit North America West Semifinal Results — Alex Gazan, Patrick Vellner Notch Wins

2023 CrossFit North America West Semifinal Results — Alex Gazan, Patrick Vellner Notch Wins

May 31, 2023
An Exercise in Repurposing and Design

An Exercise in Repurposing and Design

May 31, 2023
  • Blog
  • Privacy Policy
  • Disclaimer
  • Terms and Conditions
  • Contact us

© 2021 News.21av - Popular News & magazine powred by Get solutions.

No Result
View All Result
  • Home
  • Tech News
  • Virtual reality
  • Lifestyle
  • Beauty
  • Health & Fitness
  • Equipment

© 2021 News.21av - Popular News & magazine powred by Get solutions.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In