Microsoft released its monthly security update Tuesday 10th August 2021, disclosing 44 vulnerabilities across its suite of products.
This Patch Tuesday, the breakdown of vulnerabilities includes 7 “Critical” ratings with the remaining 37 labelled as “Important”. Also in this month’s Patch Tuesday, 3 zero-days were mentioned:
Microsoft has put out a warning about one of the vulnerabilities which hackers are particularly interested in exploiting. Krebsonsecurity.com goes on to explain that the vulnerability CVE-2021-36948, which is a weakness in the Windows Update Medic service, allows for an attacker to escalate their privileges which could potentially grant the attacker access to areas of the system which is not intended for them.
As reported by zdnet.com, the products affected by these vulnerabilities are .NET Core & Visual Studio, ASP.NET Core & Visual Studio, Azure, Windows Update, Windows Print Spooler Components, Windows Media, Windows Defender, Remote Desktop Client, Microsoft Dynamics, Microsoft Edge (Chromium-based), Microsoft Office, Microsoft Office Word, Microsoft Office SharePoint, and more technologies.
A full list of Microsoft’s August 2021 Patches, their CVE’s severities, scores, exploits, and disclosures can be found here: SANS Internet Storm Centre.