Microsoft’s June 2021 Patch Tuesday addresses 50 vulnerabilities in Microsoft Windows, .NET Core and Visual Studio, Microsoft Office, Microsoft Edge (Chromium-based and EdgeHTML), SharePoint Server, Hyper-V, Visual Studio Code – Kubernetes Tools, Windows HTML Platform, and Windows Remote Desktop. Five vulnerabilities fixed by Microsoft’s June 2021 Patch Tuesday are rated Critical and 45 are rated Important in severity. Microsoft experts confirmed that six of these flaws are currently under active attack and three are publicly known at the time of release.
Eight of the flaws fixed by Microsoft were reported by the Zero Day Initiative (ZDI), other issues were reported by Google’s Threat Analysis Group, Google Project Zero, Check Point Research, FireEye, Kaspersky, and Nixu Cybersecurity.
The six zero-day vulnerabilities actively exploited in the wild are:
Microsoft also addressed another zero-day flaw, tracked as CVE-2021-31968, which is a DoS issue that affects Windows Remote Desktop Services.
Kaspersky discovered two of the zero-day vulnerabilities, so we will likely see a report coming soon explaining how they were used.
“Looking at the remaining Critical-rated bugs, the update for Defender stands out even though you likely won’t need to take any action. Microsoft regularly updates the Malware Protection Engine, so if your system is connected to the Internet, it should have already received an update.” reads the post published by the ZeroDayInitiative.
The list of issues addressed by the IT giant is available here.
(SecurityAffairs – hacking, Microsoft’s June 2021 Patch Tuesday)
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.