Read The Times Australia

Daily Bulletin

April Patch Tuesday Commentary


Microsoft has released updates for the Windows OS, Office and O365, Exchange Server, Edge (Chromium), Visual Studio, Azure DevOps, Azure AD Web Sign-in, Azure Sphere, and many other components. A total of 110 unique vulnerabilities have been resolved this month including one Zero Day (CVE-2021-28310), and four publicly disclosed vulnerabilities (CVE-2021-28458, CVE-2021-28437, CVE-2021-28312, CVE-2021-27091). 19 of the CVEs are rated as Critical, but that does not include the Win32k Zero Day.

 

Microsoft Release

Zero Day: Microsoft has resolved an Important vulnerability in Win32k, which could allow an Elevation of Privilege on Windows 10 systems (CVE-2021-28310). While only rated as Important, this vulnerability has been detected in attacks in the wild. Details from open source exploits site attackerkb.com shows the CVE as reserved and last updated on March 12, 2021, so this may have been exploited by threat actors for a month or more at this point. This is a good example of the importance of using a risk-based prioritisation approach. If you are basing your prioritisation off of vendor severity and looking at just the Critical CVEs, you may have missed this one. Fortunately for those organisations, this is part of the Windows 10 cumulative this month — which also includes Critical CVEs — but broadening your prioritisation metrics to include risk metadata like exploited, publicly disclosed, and other indicators will help to ensure you prioritise the best possible set of updates to remediate in a timely fashion.

 

Publicly Disclosed: A vulnerability exists in Windows Installer that could allow for Information Disclosure CVE-2021-28437. The vulnerability has been publicly disclosed, meaning enough information has been made publicly available to give threat actors a head start on developing a functional exploit. The CVE affects all Windows Operating Systems back to Windows 7 and Server 2008. Information Disclosure exploits in Windows Installer often allow an attacker to gain access to additional information to assist in further compromise of the system. The CVE is rated as Important. Exploit code was marked as unproven at the time of release.

 

Publicly Disclosed: A vulnerability exists in RPC Endpoint Mapper Service which could allow an attacker to Elevate Privileges (CVE-2021-27091). The vulnerability has been publicly disclosed, meaning enough information has been made publicly available to give threat actors a head start on developing a functional exploit. The CVE affects older Windows 7, Server 2008 R2 and Server 2012 systems. The CVE is rated as Important, but Proof-of-Concept code is available which could allow an attacker to more quickly develop a working exploit.

 

Publicly Disclosed: An Elevation of Privilege vulnerability has been identified in Azure ms-rest-nodeauth Library (CVE-2021-28458). The vulnerability has been publicly disclosed, meaning enough information has been made publicly available to give threat actors a head start on developing a functional exploit. The vulnerability has been rated as Important. No other release notes or articles are linked to this CVE at this time.

 

Publicly Disclosed: A vulnerability exists in Windows NTFS which could allow a Denial of Service attack CVE-2021-28312. The vulnerability has been publicly disclosed, meaning enough information has been made publicly available to give threat actors a head start on developing a functional exploit. The CVE affects Windows 10 1809 and Server 2019 and later versions. The CVE is only rated as moderate, but functional exploit code is available. This CVE should be treated as a higher risk than the severity implies.

 

Exchanges Server: Microsoft Exchange Server is getting another update this month, and based on the Pwn2Own results, there will likely be more on the way. The four CVEs resolved this month were all discovered by the NSA. All four CVEs are rated as Critical. None have a proven exploit at this time, but on the heels of serious exploit activity on Microsoft Exchange you can expect if security analysts at the NSA are finding more vulnerabilities as well as security researchers proving out exploits in the Pwn2Own competition, threat actors are also swarming around Microsoft Exchange to see what more they can find as well.

 

Low Key Month for Third Party Updates

This month, Adobe had four updates for Photoshop, Digital Editions, Bridge, and Robohelp and all rated as Priority 3. A total of 10 CVEs were resolved across the four updates and all but the RoboHelp update include Critical CVEs.

 

The reasoning behind Adobe’s prioritization is because this update resolves vulnerabilities in a product that has historically not been a target for attackers. Adobe recommends administrators install the update at their discretion.

 

This is one of the challenges of vendor severity ratings – since these applications are less likely to be targeted by threat actors, Adobe set the severity of the vulnerability lower, regardless of how many vulnerabilities are resolved or what severity those vulnerabilities may be. While historical evidence reflects Adobe’s assessment accurately, it does not remove all risk. Photoshop has had as many as nine exploited CVEs over the years, the most recent being the CVEs in 2015. Of these four updates, Photoshop is the riskiest, but all are low risk and can be resolved in the course of regular maintenance.

 

Priorities this Month:

There are a lot of vulnerabilities being resolved this month. The good news is most of them are in the OS, including the Zero Day, and three of four of the Publicly Disclosed vulnerabilities. Knocking the OS out quickly will reduce a significant amount of risk this month. Top priorities this month should include the Windows OS, Edge (Chromium), and Exchange Server.

 

Keep on the Lookout

The Zero Day Initiative’s yearly Pwn2Own challenge concluded last week. The fallout from this event will begin to occur over the 90 days following the event as vendors have this window to address the vulnerabilities exploited during the event before they are made public. As these release over the next few months, you should watch for and resolve them as quickly as possible. Products affected are:

  • Zoom: which was reportedly the nastiest of exploits executed in the competition. This exploit only requires that the user be attending a meeting. No other interaction by the user is necessary. Zoom has reportedly already made a server-side change to mitigate the vulnerability but is expected to make additional changes to better secure against this attack.
  • Microsoft Exchange experienced a completed take-over utilising a combination of an authentication bypass and local privilege escalation. Expect an Exchange Server and possibly an OS fix over the next few months to respond to this one. With recent 0-day exploits of Exchange Server, there will likely be a prompt response from Microsoft and likely corresponding response from attackers to take advantage.
  • Microsoft Teams was exploited by use of a pair of vulnerabilities allowing for the researcher to exploit code in Microsoft Teams.
  • As always, browsers are hot targets. Expect security updates for Chrome and Microsoft Edge (Chromium) using the v8 JavaScript engine, and an integer overflow in Safari which allowed an out-of-bounds write to get kernel-level code execution.
  • The Parallels Desktop was highly targeted in the virtualisation category and saw two successful exploits including multiple flaws.
  • For Operating Systems, Windows 10 and Ubuntu were both successfully exploited both to escalate privileges from user to System in the case of Win 10 and from a standard user to root in the case of Ubuntu.

More Articles …

  1. What you should know about android incentive installs
  2. 3 Must-Have Web Security Protocols
  3. The Best Digital T-Shirt Printers Around The Globe
  4. Whitehat Jr Honors The Teachers of Its Coding Classes For Kids
  5. A Comprehensive Guide to an Overhead Crane
  6. What is Offset Printing? Why It is Most Preferred Choice?
  7. 5 tips for creating the perfect PA system
  8. Keeping the bounce rate down with these special home page design practices
  9. Split System Aircon vs Window-Type Aircon: Which Should You Buy
  10. Why You Should Have Your Microwave Tested
  11. Protection That Makes A Difference: 5 Features Of The Best Home Alarm Systems
  12. How Can I Ensure The Safety Of My Employees When Using An Excavator? Top 3 Safety Procedures
  13. Thousands of Small Satellites in Orbit - What Should Be Considered
  14. Do you need an eye-test before buying reading glasses?
  15. How Can You Make Your Instagram Followers Loyal?
  16. 5G LETS YOU GO 3D
  17. How app development is being embraced by a wide range of industries
  18. 4 Types of Materials Handling Equipment You Need to Know About
  19. Why Is It Importance to Have Proper Electrical Maintenance?
  20. Why Ducted Air Conditioning Is Ideal For The Australian Climate
  21. What are 4 Great SEO Tools and Why?
  22. Rechargeable Vs. Non-Rechargeable C Batteries: The Pros and Cons
  23. How To Record a Call in Microsoft Teams Compliantly: Step-by-Step Guide
  24. Why Polycarbonate is Best For Pergola Roofing
  25. 6 Things to Consider When Buying an Electric Scooter
  26. How to Prevent Power Surges
  27. Types of Steel Lintels and Their Uses
  28. Refurbished Apple iPads – Are they worth it?
  29. Proxy server in a corporate network: Technology Advantages
  30. Top Data Science Courses in Australia
  31. Which Apps Can Improve your eBike Experience?
  32. Convert links, HTML files and images
  33. February 2021 Patch Tuesday Commentary
  34. Everything You Should Know Before You Buy Solar
  35. 5 Benefits Of Installing A VOIP Phone System In Your Business
  36. Convert PDF to PowerPoint on Windows and Your Phone
  37. A World Without Google Search
  38. The Ultimate Guide to Buying Proxies
  39. 3 Signs You Need To Change Internet Providers
  40. The Pros and Cons of Solar Energy
  41. How Modern Time Clock Software Has Improved The Time Tracking Process
  42. Patch Tuesday Commentary from Chris Goettl, Senior Director of Product Management, Security at Ivanti:
  43. The Engine Conditioning Process
  44. 3 Tech Trends You Should Keep An Eye Out For In 2021
  45. Basic Uses of Magnetic Tapes
  46. Top Productivity Apps For Writers
  47. Periodic vehicle maintenance
  48. Tire Rotation Every 6,000 Miles
  49. Everything You Wanted To Know About Solar Penrith
  50. How Available is Gigabit Fibre in Australia in 2020?

Business News

How Telematics Helps Australian Companies Improve Productivity

Operating a commercial fleet in Australia is a uniquely demanding endeavour. Between the sprawling urban sprawl of cities like Sydney and Melbourne and the immense, unforgiving stretches of the Outb...

Daily Bulletin - avatar Daily Bulletin

Inside the Icon: The BridgeMuseum Officially Opens at the Sydney Harbour Bridge

A bold new way to experience one of Australia’s most recognisable landmarks has arrived, with BridgeClimb Sydney officially opening the all-new BridgeMuseum.  Located inside the Sydney Harbour Brid...

Daily Bulletin - avatar Daily Bulletin

Is Your Brand Showing Up in AI Search? Most Melbourne Brands Aren't.

The New Front Door Nobody Told You About Something changed. Quietly. Without a press release. The way buyers find businesses in Australia has been rewired. Not replaced, rewired. Google isn't dead...

Daily Bulletin - avatar Daily Bulletin

How Australian Businesses Can Measure SEO ROI

SEO can feel vague when you are staring at a dashboard full of numbers that do not clearly connect to revenue. The key is to measure the right signals in the right order, then tie them back to outcome...

Daily Bulletin - avatar Daily Bulletin

How Commercial Roller Shutters Improve Site Security Without Slowing Operations

Security upgrades can be frustrating when they make everyday work harder. A door that takes too long to open, creates bottlenecks at shift change, or fails at the worst time can turn “better protectio...

Daily Bulletin - avatar Daily Bulletin

Why a Document Destruction Service Still Matters for Modern Businesses

Businesses generate large volumes of information every day, from staff records and contracts to invoices, reports and customer files. While attention often focuses on how documents are stored, the way...

Daily Bulletin - avatar Daily Bulletin

Bicycle Rack Safety and Space-Smart Storage

Bike storage problems usually show up as small annoyances first: tangled handlebars, scratched frames, and bikes that topple when you pull one out. Over time, those issues become safety risks, especia...

Daily Bulletin - avatar Daily Bulletin

How to Tell if a Childcare Centre Is a Good Fit for Your Child

Choosing childcare can feel like you’re making a huge decision with limited information. Tours are short, centres are often on their best behaviour, and your child might act differently in a new space...

Daily Bulletin - avatar Daily Bulletin

Car Import Timeline: What Usually Happens at Each Stage

Importing a car into Australia can feel confusing because multiple agencies and checkpoints are involved, and the timeline is shaped as much by paperwork quality as it is by shipping speed. The most u...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

Gold Migration Lawyers in Liquidation: How the Closure Affects Your ART Appeal

If your appeal was with Gold Migration Lawyers, a recent change to how the Tribunal decides cases ...

The pressure cooker: life in urban Australia in 2026

Australian cities have always been demanding. Long commutes, rising housing costs, busy schedules a...

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...