Daily Bulletin

Business Mentor

.

Patch Tuesday Commentary from Ivanti


Microsoft released updates for Windows, Office, Azure and Visual Studio this month resolving a total of 64 vulnerabilities. The Zero Day vulnerability in MSHTML (CVE-2021-40444) has been resolved this month. Microsoft’s original mitigation guidance released on September 7      can be disabled once you have updated all Windows OSs this month. Besides the MSHTML RCE vulnerability there are also two publicly disclosed CVEs that warrant some attention this month.

 

While not the specific PrintNightmare CVE (CVE-2021-34527), one of the additional Print Spooler CVEs that was initially addressed in the August Patch Tuesday release (CVE-2021-36958) has been updated this month. The update has removed the previously defined mitigation as it no longer applies and addresses the additional concerns that were identified by researchers beyond the original fix. The vulnerability has been publicly disclosed and functional exploit code is available, so this puts further urgency on this month’s Windows OS updates.

 

The third public disclosure (CVE-2021-36968) resolves an Elevation of Privilege vulnerability in Windows DNS. This CVE applies to the legacy Windows OSs. Public disclosure gives threat actors a bit of a jump start on developing a working exploit. In this case, they could find the fact that this only affects legacy OSs as attractive, banking on the fact that companies are still running on the legacy Oss but not continuing with ESU support from Microsoft. If you fall into this group, there is yet more reason to either subscribe to Microsoft’s ESU for Windows 7 and Server 2008\2008 R2 or migrate off of these platforms as the risk of running these EoL systems continues to grow.

 

Google Chrome released a critical update today resolving 11 CVEs including two Zero Day vulnerabilities (CVE-2021-30632 and CVE-2021-30633). Adobe Acrobat and Reader updates resolve X CVEs.

Apple has also released security updates for Mac OS 11.6 and iOS 14.8 which resolve two Zero Day vulnerabilities (CVE-2021-30860 and CVE-2021-30858). CVE-2021-30860 is the vulnerability that was utilized to deploy Pegasus Spyware to a variety of Apple Devices giving near complete access to personal data on targeted devices. For iOS users you may see this available immediately, but Apple does a rolling update across iOS devices so not everyone would see an update available immediately.  Best to check back daily to see when it is available for update.

 

Adobe Acrobat and Reader (APSB21-55), Adobe Experience Manager (APSB21-82) and Adobe ColdFusion (APSB21-75) are the top three updates from Adobe this month. Acrobat and Reader resolved 26 total CVEs (13 critical), Experience Manager resolved one critical and three important CVEs, and Fusion resolved two critical CVEs.

 

Priorities this month:

  • Windows OS update to resolve the MSHTML Zero Day and the Print Spooler vulnerability
  • Google Chrome to plug two Zero Day vulnerabilities
  • Adobe Acrobat and Reader APSB21-55 to resolve the 13 critical CVEs
  • Apple MacOS and iOS updates to plug two Zero Day vulnerabilities

More Articles ...

  1. 5 Reasons to Hire an Electrician
  2. Home Automation: Its Meaning, Basics, and Working
  3. What Is the Difference between HL7 and API?
  4. Reasons Why You Need Bollards at Public Venues
  5. The Benefits of Going Solar for Every Industry
  6. 4 Tips Needed for an Efficient Working From Home Transition
  7. Radio rundown: the benefits of using UHF radios
  8. Web experts: 5 reasons to hire a professional web developer
  9. FAQs About Diesel Tanks
  10. LG leads with the triple NeON H390W Solar Panel
  11. Why Every Business In The 21st Century Needs Managed IT Services
  12. 7 Reasons why every company should have Digital Signages & Video walls
  13. What Is Cloud Hosting And How Can Your Business Benefit From It?
  14. Say No To Plastic: Sustainable Packaging Alternatives
  15. The Importance of Cloud Services for Law Firms
  16. Considerations That Affect the Cost of Residential Solar Systems
  17. What You Need to Know about Heavy Duty Equipment
  18. How to Determine When the Job Requires a Large Excavator
  19. Why data centres are important for your business needs
  20. August Patch Tuesday Commentary from Ivanti
  21. How Much Will My Electric Car Cost Me?
  22. How Can You Optimize Your Video for Search?
  23. 3 Factors to Consider When Buying a Camera for Professional use cameras for Professionals
  24. Information You Need To Provide An SEO Company Before Hiring Their Service
  25. July Patch Tuesday Commentary from Ivanti
  26. How to Choose the Best Screen Protector for Your Mobile Phone
  27. How Does the Software Developer Work in Healthcare?
  28. Better safe than very sorry: why your business needs cybersecurity audits
  29. Some of the most prominent companies on the Australian Stock Exchange: A guide
  30. Data Center Fabric and Health Insurance
  31. The Way to Digitize Cities with Real-Time Solutions
  32. What are Bookshelf Speakers? The Best and Most Affordable Ones to Use
  33. What to Look For in a Gaming Mouse
  34. How to Download Facebook Videos Online
  35. Things you need to know about Heavy Duty Equipment
  36. Patch Tuesday Commentary from Ivanti
  37. Why You Should Invest in Australia’s Solar Energy
  38. The Rise and Rise of Managed Freelancing According to Gawdo.com
  39. What Are the Features of Reliable Solar Panel Suppliers
  40. 5 Reasons You Need A Level 2 Electrician
  41. How to Use Device Fingerprinting for Fraud Prevention
  42. 7 Warning Signs Of Faulty Electrical Wiring
  43. A Complete Guide to Machine Safety
  44. Mobile Surfing Apps: Mixing Business with Pleasure
  45. May Patch Tuesday Commentary
  46. A Perfect Guide To Buy A Smartphone
  47. Which is the Best Rechargeable Torch?
  48. Staying Connected: The Importance of Fast NBN Connection
  49. All You Need to Know About PEPPOL
  50. Can your phone capture your movements and pinpoint your whereabouts?

Business News

The Science Behind Bong Percs: How Different Perc Types Affect Your Smoking Experience

Introduction: As a seasoned aficionado of all things bongs, I've witnessed firsthand the transformative impact that perc technology has had on the smoking experience. In this comprehensive blog post...

The Bong Baron - avatar The Bong Baron

Comparing Wedding Catering in Sydney vs. Buffet Catering for Your Special Day

Weddings are a joyous occasion, filled with love, celebration, and, of course, food. As couples in Sydney plan their big day, a key decision is whether to opt for traditional wedding catering or buf...

Daily Bulletin - avatar Daily Bulletin

The Most Important Steps to Take When You Want To Register a Business in Australia

Undertaking the process of registering a new business in Australia is an exciting and potentially rewarding endeavour while the spirit of entrepreneurship has become prevalent over the last few ye...

Daily Bulletin - avatar Daily Bulletin

Tomorrow Business Growth