Security News > 2021 > June > June 2021 Patch Tuesday: Microsoft fixes six actively exploited zero-days

Microsoft has fixed 50 security vulnerabilities, six of which are actively exploited zero-days.
On this June 2021 Patch Tuesday, Microsoft has splatted 5 critical and 45 important bugs.
"At first glance, I thought this Patch Tuesday was going to be a light one - until I started digging into the technical details and uncovered a number of 'exploitation detected' vulnerabilities," said Kevin Breen, Director of Cyber Threat Research at Immersive Labs.
CVE-2021-33739 is an elevation of privilege zero-day vulnerability in the Microsoft Desktop Window Manager Core Library.
"For context, Microsoft patched two elevation of privilege vulnerabilities in February and April which appear to be linked to a threat actor known as BITTER APT. In the case of CVE-2021-28310, researchers linked the flaw to the dwmcore.dll file. Given that CVE-2021-33739 is credited to the same researchers who found CVE-2021-1732 in February, and was discovered in the same core library as CVE-2021-28310, it is feasible this is another zero-day being leveraged by the same BITTER APT group," commented Satnam Narang, staff research engineer at Tenable.
Among the fixed vulnerabilities the most critical one is an Improper Authentication vulnerability in SAP NetWeaver AS ABAP and ABAP Platform that can be used to bypass protection against external calls.
News URL
http://feedproxy.google.com/~r/HelpNetSecurity/~3/8kfS3vUWc0c/
Related news
- Microsoft April 2025 Patch Tuesday fixes exploited zero-day, 134 flaws (source)
- Patch Tuesday: Microsoft Fixes 134 Vulnerabilities, Including 1 Zero-Day (source)
- Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws (source)
- Patch Tuesday: Microsoft fixes 5 actively exploited zero-days (source)
- Microsoft's May Patch Tuesday update fails on some Windows 11 VMs (source)
- Week in review: Probing activity on Palo Alto Networks GlobalProtect portals, Patch Tuesday forecast (source)
- Microsoft: Windows CLFS zero-day exploited by ransomware gang (source)
- Microsoft fixes actively exploited Windows CLFS zero-day (CVE-2025-29824) (source)
- April's Patch Tuesday leaves unlucky Windows Hello users unable to login (source)
- Emergency patch for potential SAP zero-day that could grant full system control (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-06-08 | CVE-2021-33739 | Unspecified vulnerability in Microsoft products Microsoft DWM Core Library Elevation of Privilege Vulnerability | 0.0 |
2021-04-13 | CVE-2021-28310 | Out-of-bounds Write vulnerability in Microsoft products Win32k Elevation of Privilege Vulnerability | 0.0 |
2021-02-25 | CVE-2021-1732 | Out-of-bounds Write vulnerability in Microsoft products Windows Win32k Elevation of Privilege Vulnerability | 0.0 |