Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT Security Bulletin ASB-2021.0117 Microsoft Patch Tuesday update for Microsoft Developer Tools for June 2021 9 June 2021 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Microsoft .NET Microsoft Visual Studio Visual Studio 2019 for Mac Visual Studio Code Operating System: Windows Mac OS Impact/Access: Increased Privileges -- Console/Physical Denial of Service -- Remote/Unauthenticated Resolution: Patch/Upgrade CVE Names: CVE-2021-31957 CVE-2021-31938 OVERVIEW Microsoft has released its monthly security patch update for the month of June 2021. This update resolves 2 vulnerabilities across the following products: [1] .NET 5.0 .NET Core 3.1 Microsoft Visual Studio 2019 version 16.10 (includes 16.0 - 16.9) Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3) Microsoft Visual Studio 2019 version 16.7 (includes 16.0 – 16.6) Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8) Visual Studio 2019 for Mac version 8.10 Visual Studio Code - Kubernetes Tools IMPACT Microsoft has given the following details regarding these vulnerabilities. Details Impact Severity CVE-2021-31938 Elevation of Privilege Important CVE-2021-31957 Denial of Service Important MITIGATION Microsoft recommends updating the software to the latest available version available on the Microsoft Update Catalog. [1]. REFERENCES [1] Microsoft Security Update Guidance https://portal.msrc.microsoft.com/en-us/security-guidance AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBYMAQqeNLKJtyKPYoAQhbTQ//ST7A9fDL4l/2rp/4MYJOSRImm3Mb19zp uTxdYykt1GRLA9gCWTX1Xf3Hz1HX4ql2I40rE1qs13EfdnngPXSaEoEsRWt3WSmb aYcwjrmcmFOk1GenNGu/1l8R9tD9DJ2x0fvLgpeD+HaKGubTUZtw80bKCJPTu7ux DyxwiLGizSv0vMQRGDM4Z4/4sMfzofpqqDarYTTjEn4za/+hkzx6e2XQjdWZ6uuN 6drgMIhbo/Ld+ll9Wo8bvWV2tXLIZcxh41Vycf51dLAWsHVN3TY73M3/VlmEWKks LOqH2DEHJwqSPYW48p4ySRuLA62tY/waKrFHrZMC+ggWwLYCFHCDl+IL27BtuZgc 9q4Bvw3p4TyZwOVYDMgQHNf6W9kOlDLu9qdYcAQKk+MZulDsyYolW/+J2iGgG3jC Xhe9cBLRYk9nHRzv2GlAjeM1jHbOPtSdd9YmkVJVW/Mq/xGETk+SJx9CoaUp9yZs ghH/LpokEuSG3N0JFFAYwLvsbTgAZFGJhYd/Ist0CBGCE+/N9h+ZirtGdwAuYitP wRew2QVaoIZW0ojgt/2mWLza1IXfb3EQSeXdHks0Sv8y0FTIA5H7OYBZRkYeeav1 3JlORvTFotD+lPyRHfUE/GAUQYy9dXlEFldN5AHqSGxZeewsux/zJ8I+gmCT7heJ 0psFQjeul2A= =LP9L -----END PGP SIGNATURE-----