CSIRT Panamá Aviso 2021-jun-10 Actualizaciones de Microsoft corrigen 50 fallas y7 día-cero explotados.
Gravedad: Alta
Fecha de publicación: junio 10, 2021
Última revisión: junio 10, 2021
https://msrc.microsoft.com/update-guide/releaseNote/2021-Jun
Sistemas Afectados:
.NET Core & Visual Studio
3D Viewer
Microsoft DWM Core Library
Microsoft Intune
Microsoft Office
Microsoft Office Excel
Microsoft Office Outlook
Microsoft Office SharePoint
Microsoft Scripting Engine
Microsoft Windows Codecs Library
Paint 3D
Role: Hyper-V
Visual Studio Code – Kubernetes Tools
Windows Bind Filter Driver
Windows Common Log File System Driver
Windows Cryptographic Services
Windows DCOM Server
Windows Defender
Windows Drivers
Windows Event Logging Service
Windows Filter Manager
Windows HTML Platform
Windows Installer
Windows Kerberos
Windows Kernel
Windows Kernel-Mode Drivers
Windows Network File System
Windows NTFS
Windows NTLM
Windows Print Spooler Components
Windows Remote Desktop
Windows TCP/IP
I. Descripción
Microsoft ha publicado actualizaciones de seguridad para solucionar varias vulnerabilidades que afectan a productos de Microsoft.
II. Detalle
Con la actualización de hoy, Microsoft ha corregido 50 vulnerabilidades y 7 catalogadas como de dia cero.
Tag | CVE ID | CVE Title | Severity |
---|---|---|---|
.NET Core & Visual Studio | CVE-2021-31957 | .NET Core and Visual Studio Denial of Service Vulnerability | Important |
3D Viewer | CVE-2021-31942 | 3D Viewer Remote Code Execution Vulnerability | Important |
3D Viewer | CVE-2021-31943 | 3D Viewer Remote Code Execution Vulnerability | Important |
3D Viewer | CVE-2021-31944 | 3D Viewer Information Disclosure Vulnerability | Important |
Microsoft DWM Core Library | CVE-2021-33739 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Important |
Microsoft Edge (Chromium-based) | CVE-2021-33741 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important |
Microsoft Intune | CVE-2021-31980 | Microsoft Intune Management Extension Remote Code Execution Vulnerability | Important |
Microsoft Office | CVE-2021-31940 | Microsoft Office Graphics Remote Code Execution Vulnerability | Important |
Microsoft Office | CVE-2021-31941 | Microsoft Office Graphics Remote Code Execution Vulnerability | Important |
Microsoft Office Excel | CVE-2021-31939 | Microsoft Excel Remote Code Execution Vulnerability | Important |
Microsoft Office Outlook | CVE-2021-31949 | Microsoft Outlook Remote Code Execution Vulnerability | Important |
Microsoft Office SharePoint | CVE-2021-31964 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
Microsoft Office SharePoint | CVE-2021-31963 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Critical |
Microsoft Office SharePoint | CVE-2021-31950 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
Microsoft Office SharePoint | CVE-2021-31948 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
Microsoft Office SharePoint | CVE-2021-31966 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important |
Microsoft Office SharePoint | CVE-2021-31965 | Microsoft SharePoint Server Information Disclosure Vulnerability | Important |
Microsoft Office SharePoint | CVE-2021-26420 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important |
Microsoft Scripting Engine | CVE-2021-31959 | Scripting Engine Memory Corruption Vulnerability | Critical |
Microsoft Windows Codecs Library | CVE-2021-31967 | VP9 Video Extensions Remote Code Execution Vulnerability | Critical |
Paint 3D | CVE-2021-31946 | Paint 3D Remote Code Execution Vulnerability | Important |
Paint 3D | CVE-2021-31983 | Paint 3D Remote Code Execution Vulnerability | Important |
Paint 3D | CVE-2021-31945 | Paint 3D Remote Code Execution Vulnerability | Important |
Role: Hyper-V | CVE-2021-31977 | Windows Hyper-V Denial of Service Vulnerability | Important |
Visual Studio Code – Kubernetes Tools | CVE-2021-31938 | Microsoft VsCode Kubernetes Tools Extension Elevation of Privilege Vulnerability | Important |
Windows Bind Filter Driver | CVE-2021-31960 | Windows Bind Filter Driver Information Disclosure Vulnerability | Important |
Windows Common Log File System Driver | CVE-2021-31954 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important |
Windows Cryptographic Services | CVE-2021-31201 | Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | Important |
Windows Cryptographic Services | CVE-2021-31199 | Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | Important |
Windows DCOM Server | CVE-2021-26414 | Windows DCOM Server Security Feature Bypass | Important |
Windows Defender | CVE-2021-31978 | Microsoft Defender Denial of Service Vulnerability | Important |
Windows Defender | CVE-2021-31985 | Microsoft Defender Remote Code Execution Vulnerability | Critical |
Windows Drivers | CVE-2021-31969 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Important |
Windows Event Logging Service | CVE-2021-31972 | Event Tracing for Windows Information Disclosure Vulnerability | Important |
Windows Filter Manager | CVE-2021-31953 | Windows Filter Manager Elevation of Privilege Vulnerability | Important |
Windows HTML Platform | CVE-2021-31971 | Windows HTML Platform Security Feature Bypass Vulnerability | Important |
Windows Installer | CVE-2021-31973 | Windows GPSVC Elevation of Privilege Vulnerability | Important |
Windows Kerberos | CVE-2021-31962 | Kerberos AppContainer Security Feature Bypass Vulnerability | Important |
Windows Kernel | CVE-2021-31951 | Windows Kernel Elevation of Privilege Vulnerability | Important |
Windows Kernel | CVE-2021-31955 | Windows Kernel Information Disclosure Vulnerability | Important |
Windows Kernel-Mode Drivers | CVE-2021-31952 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Important |
Windows MSHTML Platform | CVE-2021-33742 | Windows MSHTML Platform Remote Code Execution Vulnerability | Critical |
Windows Network File System | CVE-2021-31975 | Server for NFS Information Disclosure Vulnerability | Important |
Windows Network File System | CVE-2021-31974 | Server for NFS Denial of Service Vulnerability | Important |
Windows Network File System | CVE-2021-31976 | Server for NFS Information Disclosure Vulnerability | Important |
Windows NTFS | CVE-2021-31956 | Windows NTFS Elevation of Privilege Vulnerability | Important |
Windows NTLM | CVE-2021-31958 | Windows NTLM Elevation of Privilege Vulnerability | Important |
Windows Print Spooler Components | CVE-2021-1675 | Windows Print Spooler Elevation of Privilege Vulnerability | Important |
Windows Remote Desktop | CVE-2021-31968 | Windows Remote Desktop Services Denial of Service Vulnerability | Important |
Windows TCP/IP | CVE-2021-31970 | Windows TCP/IP Driver Security Feature Bypass Vulnerability | Important |
III. Referencia a soluciones, herramientas e información
Actualizar utilizando Microsoft Windows Update o herramientas de administracion de actualizaciones centralizadas.
IV. Información de contacto
CSIRT PANAMA
Computer Security Incident Response Team Autoridad Nacional para la Innovacion Gubernamental
E-Mail: info@cert.pa
Phone: +507 520-CERT (2378)
Web: https://cert.pa
Twitter: @CSIRTPanama
Key ID: 16F2B124