15 September 2021

Microsoft’ September 2021 Patch Tuesday fixes over 60 security bugs, including MSHTML zero-day


Microsoft’ September 2021 Patch Tuesday fixes over 60 security bugs, including MSHTML zero-day

Microsoft has released software updates to resolve dozens of security vulnerabilities in Windows, Azure Open Management Infrastructure, Azure Sphere, Office Excel, PowerPoint, Word, and Access; the kernel, Visual Studio, Microsoft Windows DNS, BitLocker, and other related software.

The software updates include fixes for several critical bugs, including a remote code execution flaw in MSHTML (CVE-2021-40444), which Microsoft said was observed being exploited in a limited number of attacks. MSHTML is the main HTML component of the Windows Internet Explorer browser, it is also used in other applications.

The vulnerability is caused by improper input validation within the MSHTML component. A remote attacker can create a specially crafted Office document with a malicious ActiveX control inside, trick the victim into opening the document and execute arbitrary code on the system.

Some other notable vulnerabilities addressed with the release of this month’s Patch Tuesday include bugs affecting Windows WLAN AutoConfig Service, Microsoft Open Management Infrastructure, Microsoft Edge, Microsoft Excel, Word, Office, and Microsoft Office Access Connectivity Engine.


Back to the list

Latest Posts

Twitch downplays extent of the recent breach, says only small number of customers affected

Twitch downplays extent of the recent breach, says only small number of customers affected

Twitch said that no login credentials or full credit card info data belonging to users or streamers were exposed in the data breach.
18 October 2021
REvil goes off the radar after group’s Tor sites were hijacked

REvil goes off the radar after group’s Tor sites were hijacked

At present, it is unknown who compromised the gang servers.
18 October 2021
US security agencies say ransomware hackers targeted 3 different US water facilities in 2021

US security agencies say ransomware hackers targeted 3 different US water facilities in 2021

Over the past few months, hackers have targeted wastewater plants in California, Maine and Nevada with ransomware attacks.
18 October 2021