Read The Times Australia

Daily Bulletin

July Patch Tuesday Commentary from Ivanti


July Patch Tuesday is shaping up to be a busy one. With the recent PrintNightmare out-of-band update, the upcoming Oracle quarterly CPU, a lineup of updates from Adobe including Acrobat and Reader, Mozilla Firefox and Firefox ESR, and the typical lineup of Microsoft monthly updates, there will be a lot to prioritize for your vulnerability remediation efforts this month.

 

Starting with PrintNightmare CVE-2021-34527, which was identified after the June patch Tuesday update as another vulnerability in the Print Spooler that needed to be resolved, Microsoft quickly released out-of-band security updates for most operating systems. Updates are available for Windows 7 and Server 2008/2008 R2 if you have an Extended Security Update (ESU) subscription. They also provided a support article on how the updates work and some additional configuration options. If you have not already deployed the out-of-band update you can just update the July OS updates to resolve the three new Zero Day vulnerabilities along with this CVE.

 

Microsoft resolved 117 unique CVEs, 10 of which are rated as Critical. There are three Zero Day vulnerabilities, and five public disclosures. There is a small bit of good news. All three Zero Day vulnerabilities and three of five of the publicly disclosed vulnerabilities are resolved by deploying the July OS updates. The updates this month affect the Windows OS, Office 365, Sharepoint, Visual Studio, and a number of modules and components (details can be found in the release notes).

 

Risk-Based Prioritization:

 

As you look at the vulnerabilities resolved by vendors in this Patch Tuesday update it is important to consider more than Vendor Severity and CVSS score in your assessment. If you do not have additional metrics to determine risk it is very possible you could be missing some of the more impactful updates. A good example of how the vendor algorithms used to define severity can give a bit of false sense of security can be found in this month’s Zero Day lineup. Two of the CVEs are only rated by Microsoft as Important, yet they were actively being exploited before the update was released. The CVSSv3 score for the Critical CVE is actually lower than the two Important CVEs. According to analysts like Gartner, adopting a risk-based approach to vulnerability management can reduce the number of data breach incidents each year by up to 80% (Gartner Forecast Analysis: Risk-Based Vulnerability Management 2019).

 

Zero Day Vulnerabilities:

 

CVE-2021-31979 is an Elevation of Privilege vulnerability in the Windows Kernel. This vulnerability has been detected in attacks in the wild. Microsoft severity for this CVE is rated as Important and CVSSv3 score is 7.8. The vulnerability affects Windows 7, Server 2008 and later Windows OS versions.

 

CVE-2021-33771 is an Elevation of Privilege vulnerability in the Windows Kernel. This vulnerability has been detected in attacks in the wild. Microsoft severity for this CVE is rated as Important and CVSSv3 score is 7.8. The vulnerability affects Windows 8.1, Server 2012 R2 and later Windows OS versions.

 

CVE-2021-34448 is a Memory Corruption vulnerability in Windows Scripting Engine that could allow an attacker to target a user to remotely execute code on the affected system.

 

In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability. However, an attacker would have no way to force the user to visit the website. Instead, an attacker would have to convince the user to click a link, typically by way of an enticement in an email or Instant Messenger message, and then convince the user to open the specially crafted file.

 

Microsoft severity for this CVE is rated as Critical and CVSSv3 score is 6.8. The vulnerability affects Windows 7, Server 2008 and later Windows OS versions.

Publicly Disclosed:

  • CVE-2021-33781 is a Security Feature Bypass in the Active Directory Service. This vulnerability has been publicly disclosed. Microsoft severity for this CVE is rated as Important and CVSSv3 score is 8.1. The vulnerability affects Windows 10, Server 2019 and later Windows OS versions.
  • CVE-2021-33779 is a Security Feature Bypass in the Windows ADFS Security. This vulnerability has been publicly disclosed. Microsoft severity for this CVE is rated as Important and CVSSv3 score is 8.1. The vulnerability affects Server 2016, 2019, 2004, 20H2 and Core Windows Server versions.
  • CVE-2021-34492 is a Certificate Spoofing vulnerability in the Windows OS. This vulnerability has been publicly disclosed. Microsoft severity for this CVE is rated as Important and CVSSv3 score is 8.1. The vulnerability affects Windows 7, Server 2008 and later Windows OS versions.
  • CVE-2021-34473 is a Remote Code Execution vulnerability in Microsoft Exchange Server. This vulnerability has been publicly disclosed. Microsoft severity for this CVE is rated as Critical and CVSSv3 score is 9.0.  The vulnerability affects Exchange Server 2013u23, 2016u19, 2016u20, 2019u8, 2019u9.
  • CVE-2021-34523 is an Elevation of Privilege vulnerability in Microsoft Exchange Server. This vulnerability has been publicly disclosed. Microsoft severity for this CVE is rated as Important and CVSSv3 score is 9.1.  The vulnerability affects Exchange Server 2013u23, 2016u19, 2016u20, 2019u8, 2019u9.

 

Third Party Updates:

 

Oracle will be releasing their quarterly Critical Patch Update or CPU on July 20th. This will include updates for Oracle Java SE, MySQL, Fusion Middleware, and many other Oracle products. These will all include security fixes, CVSSv3.1 details including attack complexity, if it is remotely exploitable and other details that can help understand how to prioritize urgency of applying these updates.

 

Adobe released updates for five products as part of their July Patch Tuesday update. The updates for Adobe Bridge, Dimension, Illustrator, and Framemaker are rated by Adobe as Priority 3. Each resolves at least one Critical CVE. Adobe’s priority takes into account severity of the vulnerabilities as well as the likelihood of an attacker targeting the product they apply to. Adobe Priority 1 indicates at least one CVE included in the release is actively being exploited. Priority 3 are products less likely to be targeted and low history of previously exploited vulnerabilities. While not urgent, these four product updates should be resolved in a reasonable timeframe. The urgency this month would be the Adobe Acrobat and Reader update (APSB21-51) which resolves 19 CVEs, 14 of which are rated as Critical. The Priority set by Adobe on this update is Priority 2. Three of the Critical CVEs are rated as 8.8 CVSSv3 and if exploited could allow remote code execution. While none of the CVEs are known to be exploited, Acrobat and Reader are more widely available on systems for a threat actor to target.

 

Mozilla released updates for Firefox and Firefox ESR including fixes for 9 CVEs. Mozilla rates five of the CVEs as High impact. More details can be found in MFSA2021-28.

 

Recommended Priorities:

  • The top priority this month is the Windows OS update. Three additional Zero Day vulnerabilities being resolved, and for those who have not yet deployed the out-of-band PrintNightmare fix, that would make four Zero Days along with three publicly disclosed vulnerabilities.
  • Microsoft Exchange has two publicly disclosed vulnerabilities and CVE-2021-31206 which was first made known as part of the Pwn2Own contest a few months back. So while Exchange has had a short reprieve after some hard back-to-back months of updates, this one should be investigated and resolved as soon as practical.
  • Third Party Updates for Adobe Acrobat and Reader, and Mozilla Firefox should be a priority. PDF and Browser applications are easy targets for attackers to target by exploiting a user with phishing attacks and other user targeted methods.

 

More Articles …

  1. How to Choose the Best Screen Protector for Your Mobile Phone
  2. How Does the Software Developer Work in Healthcare?
  3. Better safe than very sorry: why your business needs cybersecurity audits
  4. Some of the most prominent companies on the Australian Stock Exchange: A guide
  5. Data Center Fabric and Health Insurance
  6. The Way to Digitize Cities with Real-Time Solutions
  7. What are Bookshelf Speakers? The Best and Most Affordable Ones to Use
  8. What to Look For in a Gaming Mouse
  9. How to Download Facebook Videos Online
  10. Things you need to know about Heavy Duty Equipment
  11. Patch Tuesday Commentary from Ivanti
  12. Why You Should Invest in Australia’s Solar Energy
  13. The Rise and Rise of Managed Freelancing According to Gawdo.com
  14. What Are the Features of Reliable Solar Panel Suppliers
  15. 5 Reasons You Need A Level 2 Electrician
  16. How to Use Device Fingerprinting for Fraud Prevention
  17. 7 Warning Signs Of Faulty Electrical Wiring
  18. A Complete Guide to Machine Safety
  19. Mobile Surfing Apps: Mixing Business with Pleasure
  20. May Patch Tuesday Commentary
  21. A Perfect Guide To Buy A Smartphone
  22. Which is the Best Rechargeable Torch?
  23. Staying Connected: The Importance of Fast NBN Connection
  24. All You Need to Know About PEPPOL
  25. Can your phone capture your movements and pinpoint your whereabouts?
  26. How to fix MP4 video not playing in VLC
  27. What’s new in the world of cybersecurity?
  28. Everything You Need to Know About Soil Stabilisation in 2021
  29. Here is a way to save money with network security
  30. April Patch Tuesday Commentary
  31. What you should know about android incentive installs
  32. 3 Must-Have Web Security Protocols
  33. The Best Digital T-Shirt Printers Around The Globe
  34. Whitehat Jr Honors The Teachers of Its Coding Classes For Kids
  35. A Comprehensive Guide to an Overhead Crane
  36. What is Offset Printing? Why It is Most Preferred Choice?
  37. 5 tips for creating the perfect PA system
  38. Keeping the bounce rate down with these special home page design practices
  39. Split System Aircon vs Window-Type Aircon: Which Should You Buy
  40. Why You Should Have Your Microwave Tested
  41. Protection That Makes A Difference: 5 Features Of The Best Home Alarm Systems
  42. How Can I Ensure The Safety Of My Employees When Using An Excavator? Top 3 Safety Procedures
  43. Thousands of Small Satellites in Orbit - What Should Be Considered
  44. Do you need an eye-test before buying reading glasses?
  45. How Can You Make Your Instagram Followers Loyal?
  46. 5G LETS YOU GO 3D
  47. How app development is being embraced by a wide range of industries
  48. 4 Types of Materials Handling Equipment You Need to Know About
  49. Why Is It Importance to Have Proper Electrical Maintenance?
  50. Why Ducted Air Conditioning Is Ideal For The Australian Climate

Business News

Designing Eco-Friendly Custom Water Bottles for Your Next Event

The Evolution of Sustainable Event Merchandise Event planning has undergone a massive transformation over the last decade. Gone are the days when organizers could hand out cheap, single use plastic...

Daily Bulletin - avatar Daily Bulletin

Why Choosing a Professional Florist Melbourne Makes Flower Delivery Impactful

Flowers have a great power to speak when humans cannot express their feelings with right words. Flowers are the best gifts when you are celebrating a birthday or welcoming a newborn child into your fa...

Daily Bulletin - avatar Daily Bulletin

The Business Case for Choosing Australian Fabricators Over Imported Alternatives

For a long time, you might have defaulted to overseas suppliers when sourcing fabricated metal components for a project. The unit price was lower on paper, and the maths seemed straightforward. That...

Daily Bulletin - avatar Daily Bulletin

Australian organisations are relying on business continuity plans built for a far more predictable world

Tariff escalations, supply chain fragility, geopolitical events, and the ongoing threat of cyber disruption have reshaped the risk environment facing Australian organisations. The problem is that ma...

Daily Bulletin - avatar Daily Bulletin

How to Rent a Car for Uber in Melbourne: What Every New Driver Needs to Know

Starting out as an Uber driver in Melbourne is not as complicated as it sounds but getting the vehicle right is where most new drivers get stuck. Uber has strict requirements around vehicle age, condi...

Daily Bulletin - avatar Daily Bulletin

When Should You Speak to a Lawyer About a Legal Issue?

Legal issues can begin with a simple question, then become harder to manage once formal steps are involved. Many people wait until a matter feels urgent before seeking guidance, even though earlier ...

Daily Bulletin - avatar Daily Bulletin

The strategic rise of Bali as Australia’s next essential healthcare support hub

As Australian healthcare providers grapple with unprecedented operational bottlenecks, a new nearshore model is quietly transforming patient care delivery. Forward-thinking organisations,  including...

Daily Bulletin - avatar Daily Bulletin

Cost Savings and Benefits of Using Used Pallets in Logistics

In today’s competitive logistics and supply chain industry, businesses are constantly looking for ways to reduce operational costs without compromising efficiency and reliability. One of the most prac...

Daily Bulletin - avatar Daily Bulletin

How Fulfilment Services in Australia Help Businesses Scale Efficiently

The growth of e-commerce and modern retail has transformed customer expectations. Consumers now expect fast shipping, accurate order processing, and seamless delivery experiences regardless of where...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

Why Every Workplace Should Take Emergency Preparedness Seriously

Emergency planning is one of those things many workplaces know they should think about, but it oft...

Why Clearer Communication Still Matters in a Digital-First Business

It’s never been easier for businesses to communicate, but that doesn’t mean they’re always communica...

What Happens After You Lodge a BYDA Enquiry? The Step Most Excavation Projects Miss

Every excavation project in Australia — from a backyard deck footing to a multi-storey commercial bu...

How to Choose the Right Dentist on the Gold Coast

Finding a dentist you trust is one of those decisions that quietly affects your health for years, ...

The Hidden Engineering Problem Inside Australia's Older Housing Stock

A significant share of Australian homes were built for a way of living that no longer exists. Houses...

DIY Rodent Control Vs Professional Help: When Is It Time To Call The Experts?

Rodents are one of the most frustrating pest problems for Australian property owners. Rats and mic...

Lighting Shop in Perth: How The Right Lighting Can Transform Your Home And Business

The right lighting can completely change the look, feel, and functionality of any space. Whether it ...

Traffic Light System Solutions For Safer And More Efficient Traffic Management

Modern cities and growing communities rely heavily on effective traffic management to ensure safety...

Gold Migration Lawyers in Liquidation: How the Closure Affects Your ART Appeal

If your appeal was with Gold Migration Lawyers, a recent change to how the Tribunal decides cases ...