{"id":8442,"date":"2021-06-18T13:17:10","date_gmt":"2021-06-18T20:17:10","guid":{"rendered":"https:\/\/webdev.securin.xyz\/?post_type=patch_watch&p=8442"},"modified":"2023-03-03T14:26:57","modified_gmt":"2023-03-03T21:26:57","slug":"may-2021-patch-watch-digest","status":"publish","type":"patch_watch","link":"https:\/\/webdev.securin.xyz\/patch_watch\/may-2021-patch-watch-digest\/","title":{"rendered":"May 2021: Patch Watch Digest"},"content":{"rendered":"
26 vendors released security patches for 811 vulnerabilities, including 150 CVEs with known exploits.<\/a><\/strong><\/p>\n<\/li>\n 4 vulnerabilities that got patched in May were red-flagged by CISA.<\/a><\/strong><\/p>\n<\/li>\n 343 Old vulnerabilities have been patched.<\/a><\/strong><\/p>\n<\/li>\n Microsoft fixed 55 bugs, including 3 zero days.<\/a><\/strong><\/p>\n<\/li>\n<\/ul>\n We have 150 vulnerabilities that are known exploits. Here is our analysis\u00a0 \u2013<\/p>\n 1 CVE alerted by CISA.<\/p>\n<\/li>\n 62 CVEs have RCE capabilities.<\/p>\n<\/li>\n 17 CVE with Privilege Escalation capabilities.<\/p>\n<\/li>\n 33 CVEs are associated with Denial of Service.<\/p>\n<\/li>\n 27 are linked to Webapp exploits.<\/p>\n<\/li>\n 19 CVEs are rated critical and 42 are of high severity.<\/p>\n<\/li>\n<\/ul>\n Interestingly, when we looked at this data for our patchwatch blogs in May, we found that 33 vulnerabilities were weaponized. By the end of the month when we analyzed the data again we see that 150 vulnerabilities now have known exploits. The rate of weaponization rose from 3% to 19% within a month therefore we urge security teams to prioritize these vulnerabilities for patches.<\/p>\n Click here for our analysis and download patches.<\/a><\/p>\n <\/p>\n Security updates for 346 old vulnerabilities (ranging from 2004 to 2020) have been released.<\/p>\n 102 CVEs have known exploits.<\/p>\n<\/li>\n 38 CVEs are classified as RCE bugs.<\/p>\n<\/li>\n 14 CVEs linked with Privilege escalation.<\/p>\n<\/li>\n 2 CVEs have been alerted by CISA.<\/p>\n<\/li>\n 26 CVE is rated critical and 75 of high severity.<\/p>\n<\/li>\n<\/ul>\n <\/p>\n Click here for our analysis and download patches.<\/a><\/p>\n Microsoft issued patches for 55 security vulnerabilities, including three zero-days \u00a0(CVE-2021-31207<\/a>,\u00a0 CVE-2021-31200<\/a>,\u00a0 CVE-2021-31204<\/a>).<\/p>\n Check out our Microsoft patch watch edition here.<\/a><\/p>\n CISA has published warning alerts for 4 vulnerabilities (CVE-2021-1531<\/a>, CVE-2020-7774<\/a>, CVE-2020-4033<\/a>, CVE-2021-21101<\/a>) –<\/p>\n 1 CVEs has been weaponized with Privilege Escalation capabilities.<\/p>\n<\/li>\n 1 CVEs is rated critical, and 2 of high severity.<\/p>\n<\/li>\n The Common Weakness Enumeration (CWE) assigned to these vulnerabilities are CWE-78, CWE – 79, CWE – 20, and CWE – 125. Notably, these all are classified under the 2020 CWE Top 10 Most Dangerous Software Weaknesses<\/a>.<\/p>\n<\/li>\n<\/ul>\n Click here for our analysis and download patches.<\/a><\/p>\n <\/p>\n<\/a>Weaponized Vulnerabilities<\/strong><\/h2>\n
\n
<\/a>Old Vulnerabilities Patched in May 2021<\/strong><\/h2>\n
\n
<\/a>Microsoft May Patches 2021<\/strong><\/h2>\n
<\/a>CISA Alerts<\/strong><\/h2>\n
\n