{"id":8528,"date":"2021-10-11T18:28:15","date_gmt":"2021-10-12T01:28:15","guid":{"rendered":"https:\/\/webdev.securin.xyz\/?post_type=patch_watch&p=8528"},"modified":"2023-03-03T14:10:02","modified_gmt":"2023-03-03T21:10:02","slug":"september-2021-patch-watch-digest","status":"publish","type":"patch_watch","link":"https:\/\/webdev.securin.xyz\/patch_watch\/september-2021-patch-watch-digest\/","title":{"rendered":"September 2021: Patch Watch Digest"},"content":{"rendered":"
49 vendors released security patches for 816 vulnerabilities, including 79 CVEs with known exploits.<\/a><\/p>\n<\/li>\n 20 vulnerabilities that were patched in September had been red-flagged by CISA.<\/a><\/p>\n<\/li>\n 192 old vulnerabilities have been patched.<\/a><\/p>\n<\/li>\n Microsoft fixed 60 bugs, including 2 zero days.<\/a><\/p>\n<\/li>\n<\/ul>\n We have 79 vulnerabilities that are known exploits. Here is our analysis \u2013<\/p>\n 5 CVEs are associated with ransomware strains that include Atom Silo, Maze, and Cring.<\/p>\n<\/li>\n 4 CVEs are linked to APT 1.<\/p>\n<\/li>\n 9 Malware groups (OceanSalt, Auriga, Bangat, BISCUIT, MAPIGET, TARSIP, SEASALT,\u00a0 KURTON, and HELAUTO) are correlated to 3 CVEs.<\/p>\n<\/li>\n 19 CVEs are classified as Remote Code Execution.<\/p>\n<\/li>\n 10 CVEs have Privilege Escalation capabilities.<\/p>\n<\/li>\n 5 CVEs with Cross-Site Scripting flaws.<\/p>\n<\/li>\n 21 CVEs are linked to Denial of Service.<\/p>\n<\/li>\n 19 CVEs fall into other categories.<\/p>\n<\/li>\n 18 CVEs are rated critical and 35 are of high severity.<\/p>\n<\/li>\n Of these 79 weaponized CVEs, two are alerted by CISA.<\/p>\n<\/li>\n<\/ul>\n Click here for our analysis and download patches.<\/a><\/p>\n <\/p>\n CSW Alerts<\/strong><\/p>\n Our Cyber Risk Series<\/a> and CSW blogs<\/a> have highlighted the vulnerabilities CVE-2021-34527<\/a>, CVE-2020-0549<\/a>, CVE-2020-2555,<\/a> CVE-2020-13935<\/a>, and CVE-2020-9484<\/a> which were all fixed this September. All of these vulnerabilities should be patched as soon as possible with the latest security patches.<\/p>\n 192 old vulnerabilities have been fixed by vendors, ranging from the year 2010 to 2020.<\/p>\n 4 CVEs are associated with ransomware strains that include Maze and Cring.<\/p>\n<\/li>\n 3 CVEs are linked to APT 1.<\/p>\n<\/li>\n 9 Malware groups (OceanSalt, Auriga, Bangat, BISCUIT, MAPIGET, TARSIP, SEASALT,\u00a0 KURTON, and\u00a0 HELAUTO) are correlated to 3 CVEs.<\/p>\n<\/li>\n 2 CVEs are featured by CISA.<\/p>\n<\/li>\n Of these, 36 CVEs have known exploits.<\/p>\n<\/li>\n 4 CVEs with Privilege Escalation.<\/p>\n<\/li>\n 4 CVEs are Remote Code Execution bugs.<\/p>\n<\/li>\n 27 CVEs are rated critical and 101 are of high severity.<\/p>\n<\/li>\n<\/ul>\n <\/p>\n Click here for our analysis and download patches.<\/a><\/p>\n Microsoft plugged 60 vulnerabilities including 2 zero-days. Of these 60 CVEs,\u00a0 the remote code execution vulnerability in Windows MSHTML, CVE-2021-40444, is being actively exploited by threat actors using phishing attacks. We recommend Microsoft users to address these vulnerabilities as top priority.<\/p>\n \u00a0<\/p>\n Check out our Microsoft patch watch edition here<\/a>.<\/p>\n CISA has issued alerts for 20 vulnerabilities, including 2 publicly-known exploits.<\/p>\n 1 CVE is associated with Atom Silo.<\/p>\n<\/li>\n 2 CVE is classified as a Remote Code Execution bug.<\/p>\n<\/li>\n 5 CVEs are rated critical and 13 are of high severity.<\/p>\n<\/li>\n<\/ul>\n Click here for our analysis and download patches.<\/a><\/p>\n <\/p>\n<\/a>Weaponized Vulnerabilities<\/strong><\/h2>\n
\n
<\/a>Old Vulnerabilities<\/strong><\/h2>\n
\n
<\/a>Microsoft September Patches 2021<\/strong><\/h2>\n
<\/a>CISA Alerts<\/strong><\/h2>\n
\n