Tuesday, May 24, 2022
  • About Us
  • Contact Us
  • Terms of Use
  • Privacy Policy
  • CCPA
  • DMCA
News Two Daily News
  • Home
  • Headlines
  • US News
  • World
  • Sports
  • Business
  • Technology
  • Entertainment
  • Science
  • Health
No Result
View All Result
  • Home
  • Headlines
  • US News
  • World
  • Sports
  • Business
  • Technology
  • Entertainment
  • Science
  • Health
No Result
View All Result
Morning News
No Result
View All Result
Home Technology

Microsoft Patch Tuesday, May 2021 Edition – Krebs on Security

  • Sponsored results for Microsoft Patch Tuesday, May 2021 Edition – Krebs on Security

  •  
May 12, 2021
in Technology
Patch Tuesday, Good Riddance 2020 Edition — Krebs on Security


Microsoft today released fixes to plug at least 55 security holes in its Windows operating systems and other software. Four of these weaknesses can be exploited by malware and malcontents to seize complete, remote control over vulnerable systems without any help from users. On deck this month are patches to quash a wormable flaw, a creepy wireless bug, and yet another reason to call for the death of Microsoft’s Internet Explorer (IE) web browser.

While May brings about half the normal volume of updates from Microsoft, there are some notable weaknesses that deserve prompt attention, particularly from enterprises. By all accounts, the most pressing priority this month is CVE-2021-31166, a Windows 10 and Windows Server flaw which allows an unauthenticated attacker to remotely execute malicious code at the operating system level. With this weakness, an attacker could compromise a host simply by sending it a specially-crafted packet of data.

“That makes this bug wormable, with even Microsoft calling that out in their write-up,” said Dustin Childs, with Trend Micro’s ZDI program. “Before you pass this aside, Windows 10 can also be configured as a web server, so it is impacted as well. Definitely put this on the top of your test-and-deploy list.”

Kevin Breen from Immersive Labs said the fact that this one is just 0.2 points away from a perfect 10 CVSS score should be enough to identify just how important it is to patch.

“For ransomware operators, this kind of vulnerability is a prime target for exploitation,” Breen said. “Wormable exploits should always be a high priority, especially if they are for services that are designed to be public facing. As this specific exploit would not require any form of authentication, it’s even more appealing for attackers, and any organization using HTTP.sys protocol stack should prioritize this patch.”

Breen also called attention to CVE-2021-26419 — a vulnerability in Internet Explorer 11 — to make the case for why IE needs to stand for “Internet Exploder.” To trigger this vulnerability, a user would have to visit a site that is controlled by the attacker, although Microsoft also recognizes that it could be triggered by embedding ActiveX controls in Office Documents.

“IE needs to die – and I’m not the only one that thinks so,” Breen said. “If you are an organization that has to provide IE11 to support legacy applications, consider enforcing a policy on the users that restricts the domains that can be accessed by IE11 to only those legacy applications. All other web browsing should be performed with a supported browser.”

Another curious bug fixed this month is CVE-2020-24587, described as a “Windows Wireless Networking Information Disclosure Vulnerability.” ZDI’s Childs said this one has the potential to be pretty damaging.

“This patch fixes a vulnerability that could allow an attacker to disclose the contents of encrypted wireless packets on an affected system,” he said. “It’s not clear what the range on such an attack would be, but you should assume some proximity is needed. You’ll also note this CVE is from 2020, which could indicate…



Read More News: Microsoft Patch Tuesday, May 2021 Edition – Krebs on Security

Tags: EditionKrebsMicrosoftpatchsecurityTuesday

Related Posts

Destiny 2: The Witch Queen – Season of the Haunted Official Trailer
Technology

Destiny 2: The Witch Queen – Season of the Haunted Official Trailer

May 24, 2022
AMD Ryzen 7000 Announced: 16 Cores of Zen 4, Plus PCIe 5 and DDR5 for Socket AM5,
Technology

AMD Ryzen 7000 Announced: 16 Cores of Zen 4, Plus PCIe 5 and DDR5 for Socket AM5,

May 23, 2022
5 New Features Coming to Warzone 2
Technology

5 New Features Coming to Warzone 2

May 22, 2022
BMW M4 CSL: New Detailed Photos From Villa d’Este
Technology

BMW M4 CSL: New Detailed Photos From Villa d’Este

May 21, 2022
Random: The Perfect Pokémon Graphics Don’t Exi… Oh
Technology

Random: The Perfect Pokémon Graphics Don’t Exi… Oh

May 21, 2022
Wordle 335 May 20 HINTS: Struggling with today’s Wordle? Three CLUES to help with
Technology

Wordle 335 May 20 HINTS: Struggling with today’s Wordle? Three CLUES to help with

May 20, 2022

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trend Today

Peru President, Martín Vizcarra, Survives Impeachment Vote

Peru President, Martín Vizcarra, Survives Impeachment Vote

September 19, 2020
Suspect killed in shootout with officers in Midvale, 3 others arrested

Suspect killed in shootout with officers in Midvale, 3 others arrested

September 19, 2020
Presentation Pac-12 presidents and chancellors saw before postponing sports featured

Presentation Pac-12 presidents and chancellors saw before postponing sports featured

September 18, 2020
US to declare UN sanctions reimposed on Iran despite disagreement from allies

US to declare UN sanctions reimposed on Iran despite disagreement from allies

September 17, 2020
Hurricane Sally unleashes

Hurricane Sally unleashes

September 16, 2020

EDITOR'S PICK

Mnuchin says significant new aid package still needed to help economy recover from

Vitaly Shishov, prominent Belarusian activist, found dead in Ukraine park – The

August 3, 2021
Appointments for first dose of COVID-19 vaccine drop by half in L.A. County, alarming

Appointments for first dose of COVID-19 vaccine drop by half in L.A. County, alarming

April 30, 2021
Covid-19 Live Updates: States Are Reeling After Promise of More Vaccines Unravels

Covid-19 Live Updates: States Are Reeling After Promise of More Vaccines Unravels

January 18, 2021
Coronavirus in Oregon: 750 new cases, 6 deaths as Washington tells Oregonians not to

Coronavirus in Oregon: 750 new cases, 6 deaths as Washington tells Oregonians not to

January 29, 2021

Headlines

Key takeaways from the bombshell sex abuse report by Southern Baptists

Key takeaways from the bombshell sex abuse report by Southern Baptists

May 24, 2022
Biden unveils his economic plan for countering China in Asia

Biden unveils his economic plan for countering China in Asia

May 23, 2022
Twelve people arrested at two Boston-area beaches

Twelve people arrested at two Boston-area beaches

May 22, 2022
Russia bans 963 Americans, including Biden and Harris — but not Trump

Russia bans 963 Americans, including Biden and Harris — but not Trump

May 21, 2022

Sports

Heat vs. Celtics score: Live NBA playoff updates as Boston blowing out Miami in Game

Heat vs. Celtics score: Live NBA playoff updates as Boston blowing out Miami in Game

May 24, 2022
Warriors’ Steph Curry trips on waiter’s beer tray during Game 3

Warriors’ Steph Curry trips on waiter’s beer tray during Game 3

May 23, 2022
6 takeaways as Celtics drop ugly, injury-riddled Game 3 vs. Heat

6 takeaways as Celtics drop ugly, injury-riddled Game 3 vs. Heat

May 22, 2022
Runner, 30, Dies After Collapsing at Brooklyn Half Marathon Finish Line

Runner, 30, Dies After Collapsing at Brooklyn Half Marathon Finish Line

May 21, 2022

World

EU oil embargo ‘in days’ as Ukraine isolation drives Russia closer to China

EU oil embargo ‘in days’ as Ukraine isolation drives Russia closer to China

May 24, 2022
Iran: Revolutionary Guard officer assassinated in Tehran

Iran: Revolutionary Guard officer assassinated in Tehran

May 23, 2022
Pounded by Russian offensive in the east, Ukraine rules out ceasefire

Pounded by Russian offensive in the east, Ukraine rules out ceasefire

May 22, 2022
Live Updates: Biden Signs $40 Billion Ukraine Aid Package as Russia Presses Its

Live Updates: Biden Signs $40 Billion Ukraine Aid Package as Russia Presses Its

May 21, 2022
  • About Us
  • Contact Us
  • Terms of Use
  • Privacy Policy
  • CCPA
  • DMCA

© 2020 Newstwo.net

No Result
View All Result
  • Home
  • Headlines
  • US News
  • World
  • Sports
  • Business
  • Technology
  • Entertainment
  • Science
  • Health

© 2020 Newstwo.net

Get more stuff like this
in your inbox

Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

Thank you for subscribing.

Something went wrong.

We respect your privacy and take protecting it seriously