{"id":8703,"date":"2021-04-16T07:04:57","date_gmt":"2021-04-16T14:04:57","guid":{"rendered":"https:\/\/webdev.securin.xyz\/?post_type=patch_watch&p=8703"},"modified":"2023-03-03T14:37:36","modified_gmt":"2023-03-03T21:37:36","slug":"march-microsoft-patches-89-security-vulnerabilities","status":"publish","type":"patch_watch","link":"https:\/\/webdev.securin.xyz\/patch_watch\/march-microsoft-patches-89-security-vulnerabilities\/","title":{"rendered":"March: Microsoft patches 89 security vulnerabilities"},"content":{"rendered":"
Microsoft patched 89 unique security vulnerabilities in March 2021. We analyzed these weaknesses and spotlighted important vulnerabilities that ought to be patched on priority.<\/p>\n
In March, Microsoft patched 89 vulnerabilities discovered in 2021 –<\/p>\n
RCE\/PE:\u00a0<\/strong>Remote Code Execution and Privilege Execution are two of the most dangerous weaknesses that are most exploited by malicious actors. Microsoft has fixed –<\/p>\n 45 CVEs that have been classified as RCE bugs<\/p>\n<\/li>\n 30 CVEs have Privilege Escalation capabilities<\/p>\n<\/li>\n 4 CVEs are linked to Denial of Service<\/p>\n<\/li>\n<\/ul>\n Notably four CVEs (CVE-2021-27065, CVE-2021-26855, CVE-2021-26863, CVE-2021-21300) have publicly known exploits therefore patching them would be essential.<\/p>\n Zero Day Vulnerabilities:<\/strong> Microsoft has released out-of-band patches for four Zero Day Vulnerabilities ( CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065).<\/p>\n These weaknesses exist in Microsoft exchange server and have been associated with Hafnium, Winnti Group, Tick, LuckyMouse, Websiic, Calypso, Tonto Team, Mikroceen, and Vicious Panda APT group.<\/p>\n These CVEs are also being exploited by DearCry Ransomware and are being delivered through PlugX and ShadowPad malware.<\/p>\n Six CVEs have featured in recent CISA alerts (CVE-2021-26869, CVE-2021-27065, CVE-2021-26857, CVE-2021-26855, CVE-2021-26858, CVE-2021-26867)<\/p>\n These CVEs have been red flagged by security agencies primarily because these vulnerabilities are associated with DearCry ransomware and APT groups (Hafnium, Winnti Group, Tick, LuckyMouse, Websiic, Calypso, Tonto Team, Mikroceen -Vicious Panda Group) are exploiting it to mount cyber attacks.<\/p>\n Patches are released for 47 different Microsoft products.<\/p>\n <\/p>\n\n
CISA Alerts<\/strong><\/h2>\n
Product Analysis<\/strong><\/h2>\n
Severity Scores<\/strong><\/h2>\n