Rewterz Threat Alert – Golden chickens and more eggs luring professionals through LinkedIn
April 13, 2021Rewterz Informative Update – Microsoft Security Updates for Exchange Server Vulnerabilities
April 14, 2021Rewterz Threat Alert – Golden chickens and more eggs luring professionals through LinkedIn
April 13, 2021Rewterz Informative Update – Microsoft Security Updates for Exchange Server Vulnerabilities
April 14, 2021Severity
High
Analysis Summary
CVE-2021-27091
Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by a flaw in the RPC Endpoint Mapper Service. By executing a specially-crafted program, an authenticated attacker could exploit this vulnerability to execute arbitrary code with higher privileges.
CVE-2021-28312
Microsoft Windows is vulnerable to a denial of service, caused by a flaw in the NTFS component. By persuading a victim to open a specially-crafted content, an attacker could exploit this vulnerability to cause a denial of service condition.
CVE-2021-28437
Microsoft Windows could allow a local authenticated attacker to obtain sensitive information, caused by a flaw in the Installer component. By executing specially-crafted program, an attacker could exploit this vulnerability to obtain sensitive information and then use this information to launch further attacks against the affected system.
CVE-2021-28458
Microsoft Azure ms-rest-nodeauth Library could allow a local authenticated attacker to gain elevated privileges on the system. By executing a specially-crafted program, an authenticated attacker could exploit this vulnerability to execute arbitrary code with higher privileges.
CVE-2021-28310
Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by a flaw in the Win32k component. By executing a specially-crafted program, an authenticated attacker could exploit this vulnerability to execute arbitrary code with higher privileges.
Impact
- Privilege escalation
- Denial of service
- Information disclosure
Affected Vendors
Microsoft
Affected Products
- Microsoft azure/ms-rest-nodeauth
- Microsoft Windows 7 SP1 x32
- Microsoft Windows 7 SP1 x64
- Microsoft Windows Server 2008 R2 SP1 x64
- Microsoft Windows Server 2012
Remediation
Refer to Microsoft Security Update for the complete list of affected products and their respective patches.