Daily Bulletin

Men's Weekly

.

October Patch Tuesday 2021 from Ivanti



Here is the October Patch Tuesday commentary from Chris Goettl, Vice President of Product Management, at Ivanti

October is Cybersecurity Awareness Month. It is a great time to evaluate your security strategy and ensure you are focusing on key ways to improve your overall cyber hygiene. Vulnerability management is always an area of concern as new vulnerabilities are constantly being discovered. Patch Tuesday is a specific event each month that helps companies identify and resolve security vulnerabilities in popular software, but it is primarily focused on Microsoft operating systems and applications. The challenge is all of the other vendor software in your environment that operate on different release cycles. This month we will cover the Patch Tuesday release, but also talk about a few others that you will want to be aware of.

Microsoft released updates resolving 74 new vulnerabilities (CVEs) and two re-released CVEs. There are four publicly disclosed CVEs and one zero day (CVE-2021-40449). Three of the 76 CVEs this month are rated as Critical.

This month’s updates affect the Windows OS, O365, Exchange Server, Intune, System Center, .Net Core & Visual Studio, and a number of roles in AD, ADFS, Hyper-V and DNS.

Starting with the known exploited vulnerability, CVE-2021-40449 is a Win32k Elevation of Privilege Vulnerability in the Windows OS from Windows 7 and Server 2008 up to Windows 11 and Server 2022. Microsoft only rated the vulnerability as Important by their severity scoring system, which is a good example of why organizations need to focus on vulnerability remediation based on risk. A risk-based approach to vulnerability management takes into account more real-world indicators such as known exploited, public disclosure, and usage trends by threat actors to better understand what exposures you should be focusing on first and quickest.

Microsoft resolved CVE-2021-41338, a Security Feature Bypass vulnerability in Windows AppContainer Firewall. The vulnerability has been publicly disclosed including proof-of-concept code giving threat actors a jumpstart on building an exploit to take advantage of the flaw. The vulnerability exists in Windows 10, Server 2016 and later versions.

Microsoft resolved CVE-2021-41335, an Elevation of Privilege vulnerability in the Windows Kernel. The flaw exists in Windows 7 to Windows 10 and Server 2008 to Server 2019 versions. The CVE has been publicly disclosed including proof-of-concept code giving threat actors a jumpstart on building an exploit to take advantage of the flaw. The vulnerability exists in Windows 7 and Server 2008 to Windows 10 and Server 2019.

Microsoft resolved CVE-2021-40469, a Remote Code Execution vulnerability in Windows DNS. The flaw only affects servers configured as DNS servers and affects Server 2008 to Server 2022. The vulnerability has been publicly disclosed including proof-of-concept code giving threat actors a jumpstart on building an exploit to take advantage of the flaw.

Microsoft resolved CVE-2021-33781, a Security Feature Bypass in Azure AD originally resolved      in the July 13 Patch Tuesday release. The updated added additional affected versions of Windows 10 1607 Server 2016 and Windows 11.

Adobe has released six updates including an update for Acrobat and Reader, Connect, Reader Mobile, Commerce, Campaign Standard and ops-cli. The updates for Adobe Connect (APSB21-91) and ops-cli (APSB21-88) include Critical CVEs with a CVSS base score of 9.8 out of 10. Adobe Acrobat and Reader (APSB21-104) resolves the most CVEs out of the lineup. A total of four CVEs, two of which are rated as Critical with CVSS scores of 7.8 were resolved in this update.

FoxIt PDF released updates for Windows and MacOS editions resolving many vulnerabilities. Seven CVEs were identified and a      number of IDs referenced by the Trend Zero Day Initiative and the China National Vulnerability Database were also resolved. For more details view the Foxit PDF Editor updates page.

Google Chrome has had four releases since September Patch Tuesday resolving a total of 25 CVEs.

Oracle is releasing their Quarterly CPU next Tuesday on October 19th. Be on the lookout for updates to Java, Oracle DB, Middleware and more products from Oracle.

More Articles ...

  1. Develop your software without investing too much in inhouse developers
  2. 4 Reasons You Need a Standby Generator for Your Business
  3. IoT SIM CARDS VS. TRADITIONAL SIM CARDS. WHAT'S THE DIFFERENCE?
  4. The benefits of using biomass energy
  5. Brighten Your Home Using These 4 Lighting Tips
  6. Patch Tuesday Commentary from Ivanti
  7. 5 Reasons to Hire an Electrician
  8. Home Automation: Its Meaning, Basics, and Working
  9. What Is the Difference between HL7 and API?
  10. Reasons Why You Need Bollards at Public Venues
  11. The Benefits of Going Solar for Every Industry
  12. 4 Tips Needed for an Efficient Working From Home Transition
  13. Radio rundown: the benefits of using UHF radios
  14. Web experts: 5 reasons to hire a professional web developer
  15. FAQs About Diesel Tanks
  16. LG leads with the triple NeON H390W Solar Panel
  17. Why Every Business In The 21st Century Needs Managed IT Services
  18. 7 Reasons why every company should have Digital Signages & Video walls
  19. What Is Cloud Hosting And How Can Your Business Benefit From It?
  20. Say No To Plastic: Sustainable Packaging Alternatives
  21. The Importance of Cloud Services for Law Firms
  22. Considerations That Affect the Cost of Residential Solar Systems
  23. What You Need to Know about Heavy Duty Equipment
  24. How to Determine When the Job Requires a Large Excavator
  25. Why data centres are important for your business needs
  26. August Patch Tuesday Commentary from Ivanti
  27. How Much Will My Electric Car Cost Me?
  28. How Can You Optimize Your Video for Search?
  29. 3 Factors to Consider When Buying a Camera for Professional use cameras for Professionals
  30. Information You Need To Provide An SEO Company Before Hiring Their Service
  31. July Patch Tuesday Commentary from Ivanti
  32. How to Choose the Best Screen Protector for Your Mobile Phone
  33. How Does the Software Developer Work in Healthcare?
  34. Better safe than very sorry: why your business needs cybersecurity audits
  35. Some of the most prominent companies on the Australian Stock Exchange: A guide
  36. Data Center Fabric and Health Insurance
  37. The Way to Digitize Cities with Real-Time Solutions
  38. What are Bookshelf Speakers? The Best and Most Affordable Ones to Use
  39. What to Look For in a Gaming Mouse
  40. How to Download Facebook Videos Online
  41. Things you need to know about Heavy Duty Equipment
  42. Patch Tuesday Commentary from Ivanti
  43. Why You Should Invest in Australia’s Solar Energy
  44. The Rise and Rise of Managed Freelancing According to Gawdo.com
  45. What Are the Features of Reliable Solar Panel Suppliers
  46. 5 Reasons You Need A Level 2 Electrician
  47. How to Use Device Fingerprinting for Fraud Prevention
  48. 7 Warning Signs Of Faulty Electrical Wiring
  49. A Complete Guide to Machine Safety
  50. Mobile Surfing Apps: Mixing Business with Pleasure

Business News

Why Choosing the Right Labour Hire Company on the Gold Coast Matters for Your Business

Introduction For many businesses across the Gold Coast, staffing remains one of the most significant challenges. The region’s diverse economy, with its mix of tourism, construction, hospitality, and ...

Daily Bulletin - avatar Daily Bulletin

The Importance of Scrap Metal Melbourne Recycling and Car Battery Disposal

In a growing city like Melbourne, sustainability and efficient waste management are continually growing concerns. Of the numerous categories of waste, scrap metal and used vehicle batteries stand out ...

Daily Bulletin - avatar Daily Bulletin

Workplace Health Checks: A Smart Investment for Small Business Success

Running a small business means every team member counts and when poor health leads to absenteeism or low energy, productivity and profits take a hit. Lost workdays, rising healthcare costs, and staff ...

Daily Bulletin - avatar Daily Bulletin

LayBy Deals