CSIRT Panamá Aviso 2021-ene-14 Actualizaciones de Microsoft corriguen 83 fallas.

CSIRT Panamá Aviso 2021-ene-14 Actualizaciones de Microsoft corriguen 83 fallas.
Gravedad: Alta
Fecha de publicación: enero 14, 2021
Última revisión: enero 13, 2021
https://msrc.microsoft.com/update-guide/en-us/releaseNote/2021-Jan

Sistemas Afectados:
Microsoft Windows
Microsoft Edge (EdgeHTML-based)
Microsoft Office and Microsoft Office Services and Web Apps
Microsoft Windows Codecs Library
Visual Studio
SQL Server
Microsoft Malware Protection Engine
.NET Core
.NET Repository
ASP .NET
Azure

I. Descripción
Con el lanzamiento de las actualizaciones de seguridad de enero de 2021, Microsoft lanzó correcciones para 83 vulnerabilidades en los productos de Microsoft.
De estas vulnerabilidades, 10 se clasifican como críticas, 73 como importantes.

II. Problemas Conocidos

TagCVE IDCVE TitleSeverity
.NET RepositoryCVE-2021-1725Bot Framework SDK Information Disclosure VulnerabilityImportant
ASP.NET core & .NET coreCVE-2021-1723ASP.NET Core and Visual Studio Denial of Service VulnerabilityImportant
Azure Active Directory Pod IdentityCVE-2021-1677Azure Active Directory Pod Identity Spoofing VulnerabilityImportant
Microsoft Bluetooth DriverCVE-2021-1683Windows Bluetooth Security Feature Bypass VulnerabilityImportant
Microsoft Bluetooth DriverCVE-2021-1638Windows Bluetooth Security Feature Bypass VulnerabilityImportant
Microsoft Bluetooth DriverCVE-2021-1684Windows Bluetooth Security Feature Bypass VulnerabilityImportant
Microsoft DTV-DVD Video DecoderCVE-2021-1668Microsoft DTV-DVD Video Decoder Remote Code Execution VulnerabilityCritical
Microsoft Edge (HTML-based)CVE-2021-1705Microsoft Edge (HTML-based) Memory Corruption VulnerabilityCritical
Microsoft Graphics ComponentCVE-2021-1709Windows Win32k Elevation of Privilege VulnerabilityImportant
Microsoft Graphics ComponentCVE-2021-1696Windows Graphics Component Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2021-1665GDI+ Remote Code Execution VulnerabilityCritical
Microsoft Graphics ComponentCVE-2021-1708Windows GDI+ Information Disclosure VulnerabilityImportant
Microsoft Malware Protection EngineCVE-2021-1647Microsoft Defender Remote Code Execution VulnerabilityCritical
Microsoft OfficeCVE-2021-1713Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2021-1714Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2021-1711Microsoft Office Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2021-1715Microsoft Word Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2021-1716Microsoft Word Remote Code Execution VulnerabilityImportant
Microsoft Office SharePointCVE-2021-1712Microsoft SharePoint Elevation of Privilege VulnerabilityImportant
Microsoft Office SharePointCVE-2021-1707Microsoft SharePoint Server Remote Code Execution VulnerabilityImportant
Microsoft Office SharePointCVE-2021-1718Microsoft SharePoint Server Tampering VulnerabilityImportant
Microsoft Office SharePointCVE-2021-1717Microsoft SharePoint Spoofing VulnerabilityImportant
Microsoft Office SharePointCVE-2021-1719Microsoft SharePoint Elevation of Privilege VulnerabilityImportant
Microsoft Office SharePointCVE-2021-1641Microsoft SharePoint Spoofing VulnerabilityImportant
Microsoft RPCCVE-2021-1702Windows Remote Procedure Call Runtime Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2021-1649Active Template Library Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2021-1676Windows NT Lan Manager Datagram Receiver Driver Information Disclosure VulnerabilityImportant
Microsoft WindowsCVE-2021-1689Windows Multipoint Management Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2021-1657Windows Fax Compose Form Remote Code Execution VulnerabilityImportant
Microsoft WindowsCVE-2021-1646Windows WLAN Service Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2021-1650Windows Runtime C++ Template Library Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2021-1706Windows LUAFV Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2021-1699Windows (modem.sys) Information Disclosure VulnerabilityImportant
Microsoft Windows Codecs LibraryCVE-2021-1644HEVC Video Extensions Remote Code Execution VulnerabilityImportant
Microsoft Windows Codecs LibraryCVE-2021-1643HEVC Video Extensions Remote Code Execution VulnerabilityCritical
Microsoft Windows DNSCVE-2021-1637Windows DNS Query Information Disclosure VulnerabilityImportant
SQL ServerCVE-2021-1636Microsoft SQL Elevation of Privilege VulnerabilityImportant
Visual StudioCVE-2020-26870Visual Studio Remote Code Execution VulnerabilityImportant
Windows AppX Deployment ExtensionsCVE-2021-1642Windows AppX Deployment Extensions Elevation of Privilege VulnerabilityImportant
Windows AppX Deployment ExtensionsCVE-2021-1685Windows AppX Deployment Extensions Elevation of Privilege VulnerabilityImportant
Windows CryptoAPICVE-2021-1679Windows CryptoAPI Denial of Service VulnerabilityImportant
Windows CSC ServiceCVE-2021-1652Windows CSC Service Elevation of Privilege VulnerabilityImportant
Windows CSC ServiceCVE-2021-1654Windows CSC Service Elevation of Privilege VulnerabilityImportant
Windows CSC ServiceCVE-2021-1659Windows CSC Service Elevation of Privilege VulnerabilityImportant
Windows CSC ServiceCVE-2021-1653Windows CSC Service Elevation of Privilege VulnerabilityImportant
Windows CSC ServiceCVE-2021-1655Windows CSC Service Elevation of Privilege VulnerabilityImportant
Windows CSC ServiceCVE-2021-1693Windows CSC Service Elevation of Privilege VulnerabilityImportant
Windows CSC ServiceCVE-2021-1688Windows CSC Service Elevation of Privilege VulnerabilityImportant
Windows Diagnostic HubCVE-2021-1680Diagnostics Hub Standard Collector Elevation of Privilege VulnerabilityImportant
Windows Diagnostic HubCVE-2021-1651Diagnostics Hub Standard Collector Elevation of Privilege VulnerabilityImportant
Windows DP APICVE-2021-1645Windows Docker Information Disclosure VulnerabilityImportant
Windows Event Logging ServiceCVE-2021-1703Windows Event Logging Service Elevation of Privilege VulnerabilityImportant
Windows Event TracingCVE-2021-1662Windows Event Tracing Elevation of Privilege VulnerabilityImportant
Windows Hyper-VCVE-2021-1691Hyper-V Denial of Service VulnerabilityImportant
Windows Hyper-VCVE-2021-1704Windows Hyper-V Elevation of Privilege VulnerabilityImportant
Windows Hyper-VCVE-2021-1692Hyper-V Denial of Service VulnerabilityImportant
Windows InstallerCVE-2021-1661Windows Installer Elevation of Privilege VulnerabilityImportant
Windows InstallerCVE-2021-1697Windows InstallService Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2021-1682Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows MediaCVE-2021-1710Microsoft Windows Media Foundation Remote Code Execution VulnerabilityImportant
Windows NTLMCVE-2021-1678NTLM Security Feature Bypass VulnerabilityImportant
Windows Print Spooler ComponentsCVE-2021-1695Windows Print Spooler Elevation of Privilege VulnerabilityImportant
Windows Projected File System Filter DriverCVE-2021-1663Windows Projected File System FS Filter Driver Information Disclosure VulnerabilityImportant
Windows Projected File System Filter DriverCVE-2021-1672Windows Projected File System FS Filter Driver Information Disclosure VulnerabilityImportant
Windows Projected File System Filter DriverCVE-2021-1670Windows Projected File System FS Filter Driver Information Disclosure VulnerabilityImportant
Windows Remote DesktopCVE-2021-1674Windows Remote Desktop Protocol Core Security Feature Bypass VulnerabilityImportant
Windows Remote DesktopCVE-2021-1669Windows Remote Desktop Security Feature Bypass VulnerabilityImportant
Windows Remote Procedure Call RuntimeCVE-2021-1701Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeCVE-2021-1700Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeCVE-2021-1666Remote Procedure Call Runtime Remote Code Execution VulnerabilityCritical
Windows Remote Procedure Call RuntimeCVE-2021-1664Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeCVE-2021-1671Remote Procedure Call Runtime Remote Code Execution VulnerabilityImportant
Windows Remote Procedure Call RuntimeCVE-2021-1673Remote Procedure Call Runtime Remote Code Execution VulnerabilityCritical
Windows Remote Procedure Call RuntimeCVE-2021-1658Remote Procedure Call Runtime Remote Code Execution VulnerabilityCritical
Windows Remote Procedure Call RuntimeCVE-2021-1667Remote Procedure Call Runtime Remote Code Execution VulnerabilityCritical
Windows Remote Procedure Call RuntimeCVE-2021-1660Remote Procedure Call Runtime Remote Code Execution VulnerabilityCritical
Windows splwow64CVE-2021-1648Microsoft splwow64 Elevation of Privilege VulnerabilityImportant
Windows TPM Device DriverCVE-2021-1656TPM Device Driver Information Disclosure VulnerabilityImportant
Windows Update StackCVE-2021-1694Windows Update Stack Elevation of Privilege VulnerabilityImportant
Windows WalletServiceCVE-2021-1686Windows WalletService Elevation of Privilege VulnerabilityImportant
Windows WalletServiceCVE-2021-1681Windows WalletService Elevation of Privilege VulnerabilityImportant
Windows WalletServiceCVE-2021-1690Windows WalletService Elevation of Privilege VulnerabilityImportant
Windows WalletServiceCVE-2021-1687Windows WalletService Elevation of Privilege VulnerabilityImportant

III. Referencia a soluciones, herramientas e información
Actualizar utilizando Microsoft Windows Update o herramientas de administracion de actualizaciones centralizadas.

IV. Información de contacto
CSIRT PANAMA
Computer Security Incident Response Team Autoridad Nacional para la Innovacion Gubernamental
E-Mail: info@cert.pa
Phone: +507 520-CERT (2378)
Web: https://cert.pa
Twitter: @CSIRTPanama
Facebook: http://www.facebook.com/CSIRTPanama
Key ID: 16F2B124