Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT Security Bulletin ASB-2021.0135 Microsoft Patch Tuesday update for Microsoft Extended Security Update (ESU) for July 2021 14 July 2021 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Windows 7 Windows Server 2008 Windows Server 2008 R2 Operating System: Windows Impact/Access: Execute Arbitrary Code/Commands -- Remote with User Interaction Increased Privileges -- Existing Account Denial of Service -- Remote/Unauthenticated Access Confidential Data -- Remote/Unauthenticated Provide Misleading Information -- Remote with User Interaction Unauthorised Access -- Remote with User Interaction Resolution: Patch/Upgrade CVE Names: CVE-2021-34516 CVE-2021-34514 CVE-2021-34511 CVE-2021-34507 CVE-2021-34504 CVE-2021-34500 CVE-2021-34499 CVE-2021-34498 CVE-2021-34497 CVE-2021-34496 CVE-2021-34494 CVE-2021-34492 CVE-2021-34476 CVE-2021-34457 CVE-2021-34456 CVE-2021-34448 CVE-2021-34447 CVE-2021-34446 CVE-2021-34444 CVE-2021-34442 CVE-2021-34441 CVE-2021-34440 CVE-2021-33788 CVE-2021-33786 CVE-2021-33783 CVE-2021-33782 CVE-2021-33780 CVE-2021-33765 CVE-2021-33764 CVE-2021-33757 CVE-2021-33756 CVE-2021-33754 CVE-2021-33752 CVE-2021-33750 CVE-2021-33749 CVE-2021-33746 CVE-2021-33745 CVE-2021-31979 CVE-2021-31183 Reference: ASB-2021.0134 OVERVIEW Microsoft has released its monthly security patch update for the month of July 2021. This update resolves 39 vulnerabilities across the following products: [1] Windows 7 for 32-bit Systems Service Pack 1 Windows 7 for x64-based Systems Service Pack 1 Windows Server 2008 R2 for x64-based Systems Service Pack 1 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) Windows Server 2008 for 32-bit Systems Service Pack 2 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) Windows Server 2008 for x64-based Systems Service Pack 2 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) IMPACT Microsoft has given the following details regarding these vulnerabilities. Details Impact Severity CVE-2021-31183 Denial of Service Important CVE-2021-31979 Elevation of Privilege Important CVE-2021-33745 Denial of Service Important CVE-2021-33746 Remote Code Execution Important CVE-2021-33749 Remote Code Execution Important CVE-2021-33750 Remote Code Execution Important CVE-2021-33752 Remote Code Execution Important CVE-2021-33754 Remote Code Execution Important CVE-2021-33756 Remote Code Execution Important CVE-2021-33757 Security Feature Bypass Important CVE-2021-33764 Information Disclosure Important CVE-2021-33765 Spoofing Important CVE-2021-33780 Remote Code Execution Important CVE-2021-33782 Spoofing Important CVE-2021-33783 Information Disclosure Important CVE-2021-33786 Security Feature Bypass Important CVE-2021-33788 Denial of Service Important CVE-2021-34440 Information Disclosure Important CVE-2021-34441 Remote Code Execution Important CVE-2021-34442 Denial of Service Important CVE-2021-34444 Denial of Service Important CVE-2021-34446 Security Feature Bypass Important CVE-2021-34447 Remote Code Execution Important CVE-2021-34448 Remote Code Execution Critical CVE-2021-34456 Elevation of Privilege Important CVE-2021-34457 Information Disclosure Important CVE-2021-34476 Denial of Service Important CVE-2021-34492 Spoofing Important CVE-2021-34494 Remote Code Execution Critical CVE-2021-34496 Information Disclosure Important CVE-2021-34497 Remote Code Execution Critical CVE-2021-34498 Elevation of Privilege Important CVE-2021-34499 Denial of Service Important CVE-2021-34500 Information Disclosure Important CVE-2021-34504 Remote Code Execution Important CVE-2021-34507 Information Disclosure Important CVE-2021-34511 Elevation of Privilege Important CVE-2021-34514 Elevation of Privilege Important CVE-2021-34516 Elevation of Privilege Important MITIGATION Microsoft recommends updating the software with the version made available on the Microsoft Update Catalogue for the following Knowledge Base articles. [1]. KB5004233, KB5004289, KB5004299, KB5004305, KB5004307 REFERENCES [1] Microsoft Security Update Guidance https://portal.msrc.microsoft.com/en-us/security-guidance AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBYO5hWuNLKJtyKPYoAQjBGw//VKASobBemWbwne4Szywy84S1XdQrcFS0 vxJP5mL/x4mTPBSFvvHqFQwQlPPUqSh6qhMxDI1ien8ZKPqRIEZRjQ2i8dHSg5ug XMpLTKYGzL0aKIkpe32RKLQ0kkaqGXlmo/bkZm9ObcPzPqYwkhzm9X6DgbRp89yT SWJY2NsKPv32gRtY/f44oufnojQLtfGZJA6RBA7RCAJTr3F2Jocz/JZ5iqZKgUSU UQO5MdhSFozjkqmyS3qWkaL+kWryRdrQ4EDCAT49kXjyVbc0l8zNjsF5/MlrKTRY IsDzPeUnHYhdGhE8SEW4uWOGT1p5Ijc0EXZK0FUpHmW2rs9wZRK6tT2q9+AVwxLe CnL2+YrteVsvoN8cfJ27c9acnrvEPm0jH3XsRyhBMC1cWiq/jR1VH1i++waHY3ys pB/OdMqswQuTZOqoDCKiunGdY6K77hc9qisFYxpkZ3ylpgA3brf2RSdoT+dRqYLk 5mvKbLxzqvczbD536ppuD740o1y8AyXCKzsQTF1qcLDP0rFkmThBmJmaJ/J5buSR TcX88QrOR5qz5VMS84dzwkD0+frLbwimmUUE3erX2KzCp+r0iGdDD8u654f2sCnW GYnZJjBwz3kIL/3Y6Y6snLqPGusOLLw7SIJhOSY+zUHt2LZahuTAHWXGrsZchNyp IEaNHRS+dt0= =WiIc -----END PGP SIGNATURE-----