Rewterz
Rewterz Threat Alert – Golden chickens and more eggs luring professionals through LinkedIn
April 13, 2021
Rewterz
Rewterz Informative Update – Microsoft Security Updates for Exchange Server Vulnerabilities
April 14, 2021

Rewterz Threat Advisory – Microsoft Patches Zero Day Vulnerabilities

Severity

High

Analysis Summary

CVE-2021-27091

Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by a flaw in the RPC Endpoint Mapper Service. By executing a specially-crafted program, an authenticated attacker could exploit this vulnerability to execute arbitrary code with higher privileges.

CVE-2021-28312

Microsoft Windows is vulnerable to a denial of service, caused by a flaw in the NTFS component. By persuading a victim to open a specially-crafted content, an attacker could exploit this vulnerability to cause a denial of service condition.

CVE-2021-28437 

Microsoft Windows could allow a local authenticated attacker to obtain sensitive information, caused by a flaw in the Installer component. By executing specially-crafted program, an attacker could exploit this vulnerability to obtain sensitive information and then use this information to launch further attacks against the affected system.

CVE-2021-28458

Microsoft Azure ms-rest-nodeauth Library could allow a local authenticated attacker to gain elevated privileges on the system. By executing a specially-crafted program, an authenticated attacker could exploit this vulnerability to execute arbitrary code with higher privileges.

CVE-2021-28310

Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by a flaw in the Win32k component. By executing a specially-crafted program, an authenticated attacker could exploit this vulnerability to execute arbitrary code with higher privileges.

Impact

  • Privilege escalation
  • Denial of service
  • Information disclosure

Affected Vendors

Microsoft

Affected Products

  • Microsoft azure/ms-rest-nodeauth
  • Microsoft Windows 7 SP1 x32
  • Microsoft Windows 7 SP1 x64
  • Microsoft Windows Server 2008 R2 SP1 x64
  • Microsoft Windows Server 2012

Remediation

Refer to Microsoft Security Update for the complete list of affected products and their respective patches.

https://msrc.microsoft.com/update-guide