Security News > 2021 > January > Microsoft Patch Tuesday: 83 Vulnerabilities, 10 Critical, 1 Actively Exploited

Microsoft on Tuesday released the first batch of security patches for 2021 with fixes for 83 documented security vulnerabilities, including a "Critical" bug in the Defender security product that's being actively exploited.
Security experts are urging security response personnel to pay special attention to CVE-2021-1647, which describes a remote code execution flaw in Microsoft Defender, the company's flagship anti-malware product.
The Microsoft Defender update comes with an "Exploitation detected" warning and was shipped via the Microsoft Malware Protection Engine, a utility used to clean-up remnants of known malware attacks.
Of the 83 vulnerabilities documented for January, 10 are rated "Critical," Microsoft's highest severity rating.
The January batch of patches cover serious security holes in Microsoft Office, Microsoft Office Services and Web Apps, Microsoft WIndows, Visual Studio,.
According to Dustin Childs, a research who tracks security updates for ZDI, the major bug in the Microsoft Malware Protection Engine may already be patched as the engine auto-updates as needed.
News URL
Related news
- Microsoft February 2025 Patch Tuesday fixes 4 zero-days, 55 flaws (source)
- February's Patch Tuesday sees Microsoft offer just 63 fixes (source)
- Microsoft’s Patch Tuesday Fixes 63 Flaws, Including Two Under Active Exploitation (source)
- Patch Tuesday: Microsoft Patches Two Actively Exploited Zero-Day Flaws (source)
- Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws (source)
- Choose your own Patch Tuesday adventure: Start with six zero day fixes, or six critical flaws (source)
- Patch Tuesday: Microsoft Fixes 57 Security Flaws – Including Active Zero-Days (source)
- Still Using an Older Version of iOS or iPadOS? Update Now to Patch These Critical Security Vulnerabilities (source)
- Cisco Patches Critical ISE Vulnerabilities Enabling Root CmdExec and PrivEsc (source)
- Critical RCE bug in Microsoft Outlook now exploited in attacks (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-01-12 | CVE-2021-1647 | Unspecified vulnerability in Microsoft products Microsoft Defender Remote Code Execution Vulnerability | 0.0 |