Security News > 2021 > November > Microsoft patches actively exploited Exchange, Excel zero-days (CVE-2021-42321, CVE-2021-42292)

Microsoft patches actively exploited Exchange, Excel zero-days (CVE-2021-42321, CVE-2021-42292)
2021-11-09 20:01

It's a light November 2021 Patch Tuesday from Microsoft: 55 fixed CVEs, of which two are zero-days under active exploitation: CVE-2021-42321, a Microsoft Exchange RCE, and CVE-2021-42292, a Microsoft Excel security feature bypass bug.

CVE-2021-42321, the remote code execution vulnerability in Microsoft Exchange Server 2016 and 2019, is due to issues with the validation of command-let arguments.

In a blog post published by the Exchange Team, the company recommended that the provided updates for Microsoft Exchange be installed immediately.

The in-the-wild exploitation of CVE-2021-42292, the Microsoft Excel security feature bypass zero-day, was apparently discovered by Microsoft's Security Threat Intelligence Center.

CVE-2021-42298, a Microsoft Defender RCE hole that will be plugged automatically on internet-connected systems when they receive the malware definition updates and the update for the Microsoft Malware Protection Engine.

CVE-2021-26443 a RCE affecting Microsoft Virtual Machine Bus that may allow a guest-to-host escape.


News URL

http://feedproxy.google.com/~r/HelpNetSecurity/~3/VcfraQ0u5gc/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2021-11-10 CVE-2021-42321 Unspecified vulnerability in Microsoft Exchange Server 2016/2019
Microsoft Exchange Server Remote Code Execution Vulnerability
network
low complexity
microsoft
8.8
2021-11-10 CVE-2021-42298 Code Injection vulnerability in Microsoft Malware Protection Engine
Microsoft Defender Remote Code Execution Vulnerability
local
low complexity
microsoft CWE-94
7.8
2021-11-10 CVE-2021-42292 Unspecified vulnerability in Microsoft products
Microsoft Excel Security Feature Bypass Vulnerability
local
low complexity
microsoft
7.8
2021-11-10 CVE-2021-26443 Unspecified vulnerability in Microsoft products
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
low complexity
microsoft
critical
9.0

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 473 68 2214 4928 253 7463