Read The Times Australia

Daily Bulletin

November Patch Tuesday Commentary from Ivanti


By Chris Goettl, Vice President, Product Management, at Ivanti


Microsoft has resolved a total of 55 vulnerabilities (CVE’s) in the November Patch Tuesday release, six of which are rated as Critical. The updates include the normal lineup of Windows OS, Office, Azure, and some dev tools like Visual Studio. The more painful part is likely going to be the Exchange update which contains a fix for one of two exploited vulnerabilities this month. Along with the two Zero Day vulnerabilities there are also four publicly disclosed vulnerabilities. From a risk perspective let’s start with the most severe, the two zero days.

 

Microsoft resolved a Remote Code Execution vulnerability in Microsoft Exchange server (CVE-2021-42321) that has been confirmed to be exploited in the wild. The vulnerability is rated as Important by Microsoft likely because the attacker must be authenticated to be able to exploit the vulnerability. This is a good example of the limits of vendor severity and CVSS scoring and how more information is required to fully understand what to prioritize. Exchange updates often need to be tested more by exchange admins, but an exploit in the wild puts a tighter timeframe on admins to get this vulnerability resolved.

 

Microsoft resolved a Security Feature Bypass in Microsoft Excel (CVE-2021-42292) that has been confirmed to be exploited in the wild. The exploit does not require authentication but does require user interaction. The Preview Pane is not an attack vector in this case.

 

Microsoft resolved a pair of Information Disclosure vulnerabilities in Remote Desktop Protocol (CVE-2021-38631 and CVE-2021-41371)) that could allow an RDP server administrator to read Windows RDP client passwords. These two CVEs have been publicly disclosed, but no exploits have currently been observed. The vulnerabilities are only rated as Important and the fact that the attacker would need to be an RDP admin to exploit the information disclosures would make them seem lower priority, but there could be ways for an insider threat to gain access to users credentials they should not have as an example.

 

Microsoft resolved a pair of Remote Code Execution vulnerabilities in 3D Viewer (CVE-2021-43209 and CVE-2021-43208) that have been publicly disclosed. The 3D Viewer is a Microsoft Store app and should auto update itself. You can verify the package using PowerShell to be sure the update has been applied. 3D Viewer is one of those apps that was installed by default on fresh Windows installs, but Microsoft announced that fresh installs using Windows 10 build 21332 or later would no longer install Paint 3D or 3D Viewer by default.

 

The urgency this month is on Exchange and Office updates to resolve the two Zero Day vulnerabilities. Beyond these updates is a broader response to vulnerabilities that are known to be trending amongst threat actors.      BOD 22-01 was issued to drive federal agencies to mitigate actively exploited vulnerabilities, but any organization should be taking this as good guidance to improve their vulnerability management processes.

 

Organizations who adopt a risk-based approach to vulnerability management would identify vulnerabilities that find their way onto a list like this as part of their day-to-day vulnerability management activities. Risk-based analysis of the vulnerabilities in the DHS CISA advisory can help prioritize activities for organizations to respond to, starting with the worst of them first:

  • A total 287 CVEs are released in the alert
    • 32 of them are trending in the last 30 days where attackers are focused on targeting and advancing their tactics
    • 53 CVEs are actively used by Ransomware groups
    • 54 CVEs are used by Malware authors
    • 87 CVEs are capable of a Remote Code Execution
    • 166 CVEs are Weaponized

The focus should be Trending - Ransomware - Malware - RCEs – Weaponized. A Risk-Based Vulnerability Management solution provides this type of analysis out of the box helping prioritize actions quickly and efficiently.  

Business News

How Telematics Helps Australian Companies Improve Productivity

Operating a commercial fleet in Australia is a uniquely demanding endeavour. Between the sprawling urban sprawl of cities like Sydney and Melbourne and the immense, unforgiving stretches of the Outb...

Daily Bulletin - avatar Daily Bulletin

Inside the Icon: The BridgeMuseum Officially Opens at the Sydney Harbour Bridge

A bold new way to experience one of Australia’s most recognisable landmarks has arrived, with BridgeClimb Sydney officially opening the all-new BridgeMuseum.  Located inside the Sydney Harbour Brid...

Daily Bulletin - avatar Daily Bulletin

Is Your Brand Showing Up in AI Search? Most Melbourne Brands Aren't.

The New Front Door Nobody Told You About Something changed. Quietly. Without a press release. The way buyers find businesses in Australia has been rewired. Not replaced, rewired. Google isn't dead...

Daily Bulletin - avatar Daily Bulletin

How Australian Businesses Can Measure SEO ROI

SEO can feel vague when you are staring at a dashboard full of numbers that do not clearly connect to revenue. The key is to measure the right signals in the right order, then tie them back to outcome...

Daily Bulletin - avatar Daily Bulletin

How Commercial Roller Shutters Improve Site Security Without Slowing Operations

Security upgrades can be frustrating when they make everyday work harder. A door that takes too long to open, creates bottlenecks at shift change, or fails at the worst time can turn “better protectio...

Daily Bulletin - avatar Daily Bulletin

Why a Document Destruction Service Still Matters for Modern Businesses

Businesses generate large volumes of information every day, from staff records and contracts to invoices, reports and customer files. While attention often focuses on how documents are stored, the way...

Daily Bulletin - avatar Daily Bulletin

Bicycle Rack Safety and Space-Smart Storage

Bike storage problems usually show up as small annoyances first: tangled handlebars, scratched frames, and bikes that topple when you pull one out. Over time, those issues become safety risks, especia...

Daily Bulletin - avatar Daily Bulletin

How to Tell if a Childcare Centre Is a Good Fit for Your Child

Choosing childcare can feel like you’re making a huge decision with limited information. Tours are short, centres are often on their best behaviour, and your child might act differently in a new space...

Daily Bulletin - avatar Daily Bulletin

Car Import Timeline: What Usually Happens at Each Stage

Importing a car into Australia can feel confusing because multiple agencies and checkpoints are involved, and the timeline is shaped as much by paperwork quality as it is by shipping speed. The most u...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

Gold Migration Lawyers in Liquidation: How the Closure Affects Your ART Appeal

If your appeal was with Gold Migration Lawyers, a recent change to how the Tribunal decides cases ...

The pressure cooker: life in urban Australia in 2026

Australian cities have always been demanding. Long commutes, rising housing costs, busy schedules a...

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...