{"id":8691,"date":"2021-04-19T06:47:33","date_gmt":"2021-04-19T13:47:33","guid":{"rendered":"https:\/\/webdev.securin.xyz\/?post_type=patch_watch&p=8691"},"modified":"2023-03-03T14:36:46","modified_gmt":"2023-03-03T21:36:46","slug":"march-2021-patch-watch-digest","status":"publish","type":"patch_watch","link":"https:\/\/webdev.securin.xyz\/patch_watch\/march-2021-patch-watch-digest\/","title":{"rendered":"March 2021: Patch Watch Digest"},"content":{"rendered":"
23 vendors released security patches in March for 911 vulnerabilities, including 116 CVEs with known exploits.<\/a><\/p>\n<\/li>\n 24 vulnerabilities that got patched were alerted by CISA.<\/a><\/p>\n<\/li>\n 510 old vulnerabilities have been patched.<\/a><\/p>\n<\/li>\n Microsoft fixed 89 bugs this month.<\/a><\/p>\n<\/li>\n<\/ul>\n We have 116 vulnerabilities with known exploits. Here is our analysis \u2013<\/p>\n 2 CVEs are associated with DearCry ransomware, 10 APT Groups (Hafnium, Winnti Group, Tick, LuckyMouse, Websiic, Calypso, Tonto Team, Mikroceen, Vicious Panda Group), and 2 malwares (PlugX & ShadowPad Malware).<\/p>\n<\/li>\n 3 CVE has been alerted by CISA.<\/p>\n<\/li>\n 9 CVEs have Privilege Escalation capabilities.<\/p>\n<\/li>\n 13 CVEs are associated with Remote Code Execution.<\/p>\n<\/li>\n 14 CVEs have Denial of Service.<\/p>\n<\/li>\n 8 CVEs are linked to SQL Injection.<\/p>\n<\/li>\n 47 CVEs are rated high.<\/p>\n<\/li>\n<\/ul>\n <\/p>\n Click here for our analysis and download patches.<\/a><\/p>\n 510 Old vulnerabilities have been issued security updates ranging from the year 2010 to 2020.<\/p>\n 3 CVEs are linked to BitPaymer and RansomExx ransomware.<\/p>\n<\/li>\n 6 CVEs have been alerted by CISA.<\/p>\n<\/li>\n 4 CVEs have PE capabilities.<\/p>\n<\/li>\n 3 CVEs are RCE bugs.<\/p>\n<\/li>\n 13 CVEs have Denial of Service.<\/p>\n<\/li>\n 103 CVEs are critical and 320 medium severity.<\/p>\n<\/li>\n Out of 510 Old vulnerabilities, 76 have known exploits.<\/p>\n<\/li>\n<\/ul>\n <\/p>\n Click here for our analysis and download patches.<\/a><\/p>\n Microsoft issued patches for 89 security vulnerabilities, including two zero-day.<\/p>\n Check out our Microsoft Patch Watch edition here\u00a0\u00a0<\/a><\/p>\n <\/p>\n 24 vulnerabilities have been red-flagged by CISA.<\/p>\n 3 CVEs have been weaponized with RCE\/PE.<\/p>\n<\/li>\n 4 CVEs are associated with DearCry ransomware, 10 APT Groups (Hafnium, Winnti Group, Tick, LuckyMouse, Websiic, Calypso, Tonto Team, Mikroceen, Vicious Panda Group), and 2 malware (PlugX & ShadowPad Malware).<\/p>\n<\/li>\n 9 CVEs are rated high, and 6 of medium severity.<\/p>\n<\/li>\n<\/ul>\n Click here for our analysis and download patches.<\/a><\/p>\n<\/a>Weaponized Vulnerabilities<\/strong><\/h2>\n
\n
<\/a>Old Vulnerabilities Patched in March 2021<\/strong><\/h2>\n
\n
<\/a>Microsoft March Patches 2021<\/strong><\/h2>\n
<\/a>CISA Alerts<\/strong><\/h2>\n
\n