Microsoft released its monthly security update Tuesday 13th July 2021, disclosing 117 vulnerabilities across its suite of products.
This Patch Tuesday, the breakdown of vulnerabilities include 13 “Critical” ratings with the rest labelled as “Important” and 1 vulnerability labelled as “Moderate”. Additionally, there has been 4 out of 9 zero-days that have been identified as being currently exploited in the wild. The 4 zero-days are as follows:
As reported by zdnet.com, the products affected by these vulnerabilities are Microsoft Office, SharePoint, Excel, Microsoft Exchange Server, Windows Defender, Windows Kernel, and Windows SMB.
The most interesting vulnerability to come from this month’s Patch Tuesday is CVE-2021-34527, notably called “PrintNightmare”. A similar vulnerability had been patched before, but what makes this vulnerability interesting is that guidance was developed on how to exploit it. However, the guidance was actually for an undiscovered but similar CVE; meaning there was now in-depth guidance on how to exploit an active vulnerability.
A full list of Microsoft’s July 2021 Patches, their CVE’s severities, scores, exploits, and disclosures can be found here: SANS Internet Storm Centre.