Daily Bulletin

Business Mentor

.

November Patch Tuesday Commentary from Ivanti


By Chris Goettl, Vice President, Product Management, at Ivanti


Microsoft has resolved a total of 55 vulnerabilities (CVE’s) in the November Patch Tuesday release, six of which are rated as Critical. The updates include the normal lineup of Windows OS, Office, Azure, and some dev tools like Visual Studio. The more painful part is likely going to be the Exchange update which contains a fix for one of two exploited vulnerabilities this month. Along with the two Zero Day vulnerabilities there are also four publicly disclosed vulnerabilities. From a risk perspective let’s start with the most severe, the two zero days.

 

Microsoft resolved a Remote Code Execution vulnerability in Microsoft Exchange server (CVE-2021-42321) that has been confirmed to be exploited in the wild. The vulnerability is rated as Important by Microsoft likely because the attacker must be authenticated to be able to exploit the vulnerability. This is a good example of the limits of vendor severity and CVSS scoring and how more information is required to fully understand what to prioritize. Exchange updates often need to be tested more by exchange admins, but an exploit in the wild puts a tighter timeframe on admins to get this vulnerability resolved.

 

Microsoft resolved a Security Feature Bypass in Microsoft Excel (CVE-2021-42292) that has been confirmed to be exploited in the wild. The exploit does not require authentication but does require user interaction. The Preview Pane is not an attack vector in this case.

 

Microsoft resolved a pair of Information Disclosure vulnerabilities in Remote Desktop Protocol (CVE-2021-38631 and CVE-2021-41371)) that could allow an RDP server administrator to read Windows RDP client passwords. These two CVEs have been publicly disclosed, but no exploits have currently been observed. The vulnerabilities are only rated as Important and the fact that the attacker would need to be an RDP admin to exploit the information disclosures would make them seem lower priority, but there could be ways for an insider threat to gain access to users credentials they should not have as an example.

 

Microsoft resolved a pair of Remote Code Execution vulnerabilities in 3D Viewer (CVE-2021-43209 and CVE-2021-43208) that have been publicly disclosed. The 3D Viewer is a Microsoft Store app and should auto update itself. You can verify the package using PowerShell to be sure the update has been applied. 3D Viewer is one of those apps that was installed by default on fresh Windows installs, but Microsoft announced that fresh installs using Windows 10 build 21332 or later would no longer install Paint 3D or 3D Viewer by default.

 

The urgency this month is on Exchange and Office updates to resolve the two Zero Day vulnerabilities. Beyond these updates is a broader response to vulnerabilities that are known to be trending amongst threat actors.      BOD 22-01 was issued to drive federal agencies to mitigate actively exploited vulnerabilities, but any organization should be taking this as good guidance to improve their vulnerability management processes.

 

Organizations who adopt a risk-based approach to vulnerability management would identify vulnerabilities that find their way onto a list like this as part of their day-to-day vulnerability management activities. Risk-based analysis of the vulnerabilities in the DHS CISA advisory can help prioritize activities for organizations to respond to, starting with the worst of them first:

  • A total 287 CVEs are released in the alert
    • 32 of them are trending in the last 30 days where attackers are focused on targeting and advancing their tactics
    • 53 CVEs are actively used by Ransomware groups
    • 54 CVEs are used by Malware authors
    • 87 CVEs are capable of a Remote Code Execution
    • 166 CVEs are Weaponized

The focus should be Trending - Ransomware - Malware - RCEs – Weaponized. A Risk-Based Vulnerability Management solution provides this type of analysis out of the box helping prioritize actions quickly and efficiently.  

More Articles ...

  1. October Patch Tuesday 2021 from Ivanti
  2. Develop your software without investing too much in inhouse developers
  3. 4 Reasons You Need a Standby Generator for Your Business
  4. IoT SIM CARDS VS. TRADITIONAL SIM CARDS. WHAT'S THE DIFFERENCE?
  5. The benefits of using biomass energy
  6. Brighten Your Home Using These 4 Lighting Tips
  7. Patch Tuesday Commentary from Ivanti
  8. 5 Reasons to Hire an Electrician
  9. Home Automation: Its Meaning, Basics, and Working
  10. What Is the Difference between HL7 and API?
  11. Reasons Why You Need Bollards at Public Venues
  12. The Benefits of Going Solar for Every Industry
  13. 4 Tips Needed for an Efficient Working From Home Transition
  14. Radio rundown: the benefits of using UHF radios
  15. Web experts: 5 reasons to hire a professional web developer
  16. FAQs About Diesel Tanks
  17. LG leads with the triple NeON H390W Solar Panel
  18. Why Every Business In The 21st Century Needs Managed IT Services
  19. 7 Reasons why every company should have Digital Signages & Video walls
  20. What Is Cloud Hosting And How Can Your Business Benefit From It?
  21. Say No To Plastic: Sustainable Packaging Alternatives
  22. The Importance of Cloud Services for Law Firms
  23. Considerations That Affect the Cost of Residential Solar Systems
  24. What You Need to Know about Heavy Duty Equipment
  25. How to Determine When the Job Requires a Large Excavator
  26. Why data centres are important for your business needs
  27. August Patch Tuesday Commentary from Ivanti
  28. How Much Will My Electric Car Cost Me?
  29. How Can You Optimize Your Video for Search?
  30. 3 Factors to Consider When Buying a Camera for Professional use cameras for Professionals
  31. Information You Need To Provide An SEO Company Before Hiring Their Service
  32. July Patch Tuesday Commentary from Ivanti
  33. How to Choose the Best Screen Protector for Your Mobile Phone
  34. How Does the Software Developer Work in Healthcare?
  35. Better safe than very sorry: why your business needs cybersecurity audits
  36. Some of the most prominent companies on the Australian Stock Exchange: A guide
  37. Data Center Fabric and Health Insurance
  38. The Way to Digitize Cities with Real-Time Solutions
  39. What are Bookshelf Speakers? The Best and Most Affordable Ones to Use
  40. What to Look For in a Gaming Mouse
  41. How to Download Facebook Videos Online
  42. Things you need to know about Heavy Duty Equipment
  43. Patch Tuesday Commentary from Ivanti
  44. Why You Should Invest in Australia’s Solar Energy
  45. The Rise and Rise of Managed Freelancing According to Gawdo.com
  46. What Are the Features of Reliable Solar Panel Suppliers
  47. 5 Reasons You Need A Level 2 Electrician
  48. How to Use Device Fingerprinting for Fraud Prevention
  49. 7 Warning Signs Of Faulty Electrical Wiring
  50. A Complete Guide to Machine Safety

Business News

The Most Important Steps to Take When You Want To Register a Business in Australia

Undertaking the process of registering a new business in Australia is an exciting and potentially rewarding endeavour while the spirit of entrepreneurship has become prevalent over the last few ye...

Daily Bulletin - avatar Daily Bulletin

Master Plumber, Master Painter, Master Builder… What does it Even Mean?

You’re looking around for a plumber to deal with a tricky problem. Hiring tradespeople is always a bit of a nightmare, right? Before you turn to Facebook groups to do your due diligence, there is, i...

Daily Bulletin - avatar Daily Bulletin

10 Essential Factors to Consider When Buying a Forklift

Purchasing a forklift is a significant investment for any business, whether you're in warehousing, construction, manufacturing, or logistics. With a plethora of options available in the market, it's...

Daily Bulletin - avatar Daily Bulletin

Tomorrow Business Growth