Daily Bulletin

The Times Real Estate

.

  • Written by Chris Goettl, Senior Director of Product Management, Security at Ivanti


There was an interesting start to March, with four Exchange Server exploits and an out of band update.      There is an additional Zero Day vulnerability being exploited in Internet Explorer and three publicly disclosed vulnerabilities to discuss this month. A total of 83 unique CVEs (Common Vulnerabilities and Exposures) have been resolved in Microsoft’s March Patch Tuesday update. Microsoft products affected this month include Windows OS, Office, Internet Explorer, Edge, Exchange Server, and Sharepoint, as well as many development tools and updates for Azure, Azure DevOps, and Azure Sphere

 

Exchange Zero Day Update:

Microsoft has provided a set of links to many relevant articles on the Exchange vulnerabilities, steps to identify if your environment has been compromised, mitigation options meant to protect environments short-term at the sacrifice of some functionality, and steps to take if you believe you have found indications of compromise. They also expanded the release with additional version\CU coverage.     

It is rare for Microsoft to update out of support versions of a product. This is an indication of the severity and reach of the attacks targeting the Exchange Server on-prem products. Revision note:

Reason for Revision: Microsoft is releasing security updates for CVE-2021-27065, CVE-2021-26855, CVE-2021-26857, and CVE-2021-26858 for several Cumulative Updates that are out of support, including Exchange Server 2019 CU 6, CU 5, and CU 4 and Exchange Server 2016 CU 16, CU 15, and CU14.

Please see the following for more information on the Microsoft Exchange Server Vulnerabilities:

Exploited and Publicly Disclosed Vulnerabilities:

Internet Explorer and Edge (HTML-based) browsers are being targeted by attacks in the wild. This vulnerability has also been publicly disclosed, which would allow other threats. CVE-2021-26411 is a memory corruption vulnerability that could allow an attacker to target users with specially crafted content. An attacker could utilise specially crafted websites or websites that accept user-provided content or advertisements to host content designed to exploit this vulnerability.

 

A publicly disclosed vulnerability (CVE-2021-27077) exists in Windows Win32k that could allow an attacker to elevate privileges on the affected system. The vulnerability is rated as Important and carries a base score of 7.8, but the exposure of being publicly disclosed raises the potential risk.

 

A .Net Core update from February has been re-released to provide links to release notes. The vulnerability from February had been publicly disclosed and, if exploited, could allow Remote Code Execution (CVE-2021-26701). The vulnerability has been rated as Critical and affects Microsoft .Net 5.0, .Net Core 3.1 and 2.1 as well as Visual Studio 2019 and 2017 versions.

 

March Update Priorities:

  • Exchange Server on-prem is the top priority
  • Windows OS, Internet Explorer, Edge: The browser Zero Day and other critical and publicly disclosed vulnerabilities require priority attention.
  • SharePoint Server: While not disclosed or exploited, CVE-2021-27076 is a Critical CVE and Microsoft has flagged it as Exploitation More Likely on their Exploitability Assessment.   

 

Why Professional Window Cleaning Is a Must for Melbourne Homes

Let us be honest when was the last time you cleaned your windows properly? Not just a quick wipe, but a proper clean that got into all the corners, sills, and second-storey panes. If you are like mo...

Daily Bulletin - avatar Daily Bulletin

pay.com.au unlocks untapped value through Avios and British Airways partnership

British Airways joins a growing list of transfer partners including Cathay Pacific and Thai Airways, empowering SMEs with expanded redemption options and flexibility  AUSTRALIA, 29 April 2025 — p...

Daily Bulletin - avatar Daily Bulletin

Why Ignoring a Windshield Chip Could Cost You More in the Long Run

(Source) When a stone from the road jumps to your windshield, you hear the distinctive tap. You check the glass window through your reflection to discover one tiny chip that seems insignificant. A sm...

Daily Bulletin - avatar Daily Bulletin

Top Tips for Landing Your First Job in Law

Starting your legal career is an exciting milestone – one that comes with its fair share of challenges and opportunities. Whether you’re fresh out of law school or looking to secure your first offic...

Daily Bulletin - avatar Daily Bulletin

Top 10 Soft Skills Every Legal Professional Needs

In the fast-paced and complex world of law, technical expertise is only half the equation. To truly excel, legal professionals must also master a set of soft skills that enhance their ability to com...

Daily Bulletin - avatar Daily Bulletin

Here’s How Hotels and Hospitality Venues Can Use Solar to Lower Energy Costs

With energy prices continuing to rise and sustainability becoming a growing priority for guests and stakeholders alike, hotels and hospitality venues across Australia are turning to solar power as a...

Daily Bulletin - avatar Daily Bulletin

LayBy Deals