Skip to content
NGTEdu Logo

NGTEdu

A PRODUCT OF NGTECH.CO.IN

NGTEdu Logo

NGTEdu

  • Home
  • Cyber Attacks
  • Malware
  • Vulnerabilities
  • Data Breach
  • Home
  • Cyber Attacks
  • VERT Threat Alert: November 2021 Patch Tuesday Analysis
  • Cyber Attacks
  • Vulnerabilities

VERT Threat Alert: November 2021 Patch Tuesday Analysis

4 years ago Tyler Reguly
VERT Threat Alert: May 2021 Patch Tuesday Analysis

Today’s VERT Alert addresses Microsoft’s November 2021 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-972 on Wednesday, November 10th.

In-The-Wild & Disclosed CVEs

CVE-2021-42292

Up first this month, we have a 0-day in Microsoft Excel that allows an attacker to bypass security features. This vulnerability has seen active exploitation. It is important to note that there may be multiple patches to apply to ensure you are fully protected against this vulnerability.

Microsoft has rated this as Exploitation Detected on the latest software release on the Exploitability Index.

CVE-2021-42321

This vulnerability is the second to see active exploitation this month. A vulnerability in Exchange Server could allow for code execution. Microsoft has released a blog post with details on the update. The vulnerability itself requires that the attacker be authenticated and take advantage of improper validation of cmdlet arguments.

Microsoft has rated this as Exploitation Detected on the latest software release on the Exploitability Index.

CVE-2021-38631

CVE-2021-38631 is the first of two vulnerabilities that could allow RDP client passwords to be disclosed to RDP server admins. 

Microsoft has rated this as Exploitation Less Likely on the latest software release on the Exploitability Index.

CVE-2021-41371

CVE-2021-41371 is the partner vulnerability to CVE-2021-38631, another vulnerability that could allow the RDP client passwords to be disclosed to RDP server admins.

Microsoft has rated this as Exploitation Less Likely on the latest software release on the Exploitability Index.

CVE-2021-43208

The first of two vulnerabilities discovered by Mat Powell and disclosed via ZDI. The vulnerability is triggered when parsing 3MF files and occurs due to the software not validating that an object exists before performing operations on the object. This vulnerability is likely ZDI-21-702 or ZDI-21-909.

Microsoft has rated this as Exploitation Less Likely on the latest software release on the Exploitability Index

CVE-2021-43209

The second of two vulnerabilities discovered by Mat Powell and disclosed via ZDI. The vulnerability is triggered when parsing 3MF files and occurs due to the software not validating that an object exists before performing operations on the object. This vulnerability is likely ZDI-21-702 or ZDI-21-909.

Microsoft has rated this as Exploitation Less Likely on the latest software release on the Exploitability Index.

CVE Breakdown by Tag

While historical Microsoft Security Bulletin groupings are gone, Microsoft vulnerabilities are tagged with an identifier. This list provides a breakdown of the CVEs on a per tag basis. Vulnerabilities are also colour coded to aid with identifying key issues.

  • Traditional Software
  • Mobile Software
  • Cloud or Cloud Adjacent
  • Vulnerabilities that are being exploited or that have been disclosed will be bold
TagCVE CountCVEs
Windows Fastfat Driver1CVE-2021-41377
Microsoft Office Word1CVE-2021-42296
Microsoft Edge (Chromium-based) in IE Mode1CVE-2021-41351
Windows Virtual Machine Bus1CVE-2021-26443
Windows Installer1CVE-2021-41379
Visual Studio2CVE-2021-3711, CVE-2021-42319
Microsoft Dynamics1CVE-2021-42316
Azure Sphere4CVE-2021-42300, CVE-2021-41374, CVE-2021-41375, CVE-2021-41376
Microsoft Windows Codecs Library1CVE-2021-42276
Visual Studio Code1CVE-2021-42322
Microsoft Office Excel2CVE-2021-40442, CVE-2021-42292
3D Viewer2CVE-2021-43208, CVE-2021-43209
Windows Cred SSProvider Protocol1CVE-2021-41366
Windows Kernel1CVE-2021-42285
Microsoft Exchange Server3CVE-2021-41349, CVE-2021-42305, CVE-2021-42321
Power BI1CVE-2021-41372
Windows Defender1CVE-2021-42298
Windows Desktop Bridge1CVE-2021-36957
Windows Feedback Hub1CVE-2021-42280
Windows Active Directory4CVE-2021-42278, CVE-2021-42282, CVE-2021-42287, CVE-2021-42291
Windows Diagnostic Hub1CVE-2021-42277
Windows Scripting1CVE-2021-42279
Windows RDP4CVE-2021-38631, CVE-2021-41371, CVE-2021-38665, CVE-2021-38666
Azure RTOS6CVE-2021-42301, CVE-2021-42302, CVE-2021-42303, CVE-2021-42304, CVE-2021-42323, CVE-2021-26444
Azure1CVE-2021-41373
Microsoft Office Access1CVE-2021-41368
Role: Windows Hyper-V2CVE-2021-42274, CVE-2021-42284
Windows Hello1CVE-2021-42288
Windows COM1CVE-2021-42275
Windows Core Shell1CVE-2021-42286
Microsoft Windows1CVE-2021-41356
Windows NTFS4CVE-2021-41367, CVE-2021-41378, CVE-2021-41370, CVE-2021-42283

Other Information

There were no new advisories included with the November Security Guidance.

The post ” VERT Threat Alert: November 2021 Patch Tuesday Analysis” appeared first on TripWire

Source:TripWire – Tyler Reguly

Tags: Cloud, Microsoft, Patch Tuesday, TripWire

Continue Reading

Previous Microsoft Nov. Patch Tuesday Fixes Six Zero-Days, 55 Bugs
Next 8 Best Practices for Data Security in Hybrid Environments

More Stories

  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

North Korean Hackers Abuse VS Code Auto-Run Tasks to Deploy StoatWaffle Malware

12 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More

17 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

We Found Eight Attack Vectors Inside AWS Bedrock. Here’s What Attackers Can Do with Them

18 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware

Microsoft Warns IRS Phishing Hits 29,000 Users, Deploys RMM Malware

19 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Trivy Hack Spreads Infostealer via Docker, Triggers Worm and Kubernetes Wiper

21 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems

24 hours ago [email protected] (The Hacker News)

Recent Posts

  • North Korean Hackers Abuse VS Code Auto-Run Tasks to Deploy StoatWaffle Malware
  • ⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
  • We Found Eight Attack Vectors Inside AWS Bedrock. Here’s What Attackers Can Do with Them
  • Microsoft Warns IRS Phishing Hits 29,000 Users, Deploys RMM Malware
  • Trivy Hack Spreads Infostealer via Docker, Triggers Worm and Kubernetes Wiper

Tags

Android APT Bug CERT Cloud Compliance Coronavirus COVID-19 Critical Severity Encryption Exploit Facebook Finance Google Google Chrome Goverment Hacker Hacker News High Severity Instagram iPhone Java Linux Low Severity Malware Medium Severity Microsoft Moderate Severity Mozzila Firefox Oracle Patch Tuesday Phishing Privacy QuickHeal Ransomware RAT Sim The Hacker News Threatpost TikTok TripWire VMWARE Vulnerability Whatsapp Zoom
Copyright © 2020 All rights reserved | NGTEdu.com
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More here.Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT