Detection and Response

Patch Tuesday - January 2021

|Last updated on Jan 12, 2021|1 min read
LinkedInFacebookX
Patch Tuesday - January 2021

We arrive at the first Patch Tuesday of 2021 (2021-Jan) with 83 vulnerabilities across our standard spread of products.  Windows Operating System vulnerabilities dominated this month's advisories, followed by Microsoft Office (which includes the SharePoint family of products), and lastly some from less frequent products such as Microsoft System Center and Microsoft SQL Server.

Vulnerability Breakdown by Software Family

FamilyVulnerability Count
Windows65
ESU35
Microsoft Office11
Developer Tools5
SQL Server1
Apps1
System Center1
Azure1
Browser1

Microsoft Defender Remote Code Execution Vulnerability (CVE-2021-1647)

CVE-2021-1647 is marked as a CVSS 7.8, actively exploited, remote code execution vulnerability through the Microsoft Malware Protection Engine (mpengine.dll) between version 1.1.17600.5 up to 1.1.17700.4.

As a default, Microsoft's affected antimalware software will automatically keep the Microsoft Malware Protection Engine up to date. What this means, however, is that no further action is needed to resolve this vulnerability unless non-standard configurations are used.  

This vulnerability affects Windows Defender or the supported Endpoint Protection pieces of the System Center family of products (2012, 2012 R2, and namesake version: Microsoft System Center Endpoint Protection).

Patching Windows Operating Systems Next

Another confirmation of the standard advice of prioritizing Operating System patches whenever possible is that 11 of the 13 top CVSS-scoring (CVSSv3 8.8) vulnerabilities addressed in this month's Patch Tuesday would be immediately covered through these means. As an interesting observation, the Windows Remote Procedure Call Runtime component appears to have been given extra scrutiny this month.  This RPC Runtime component accounts for the 9 of the 13 top CVSS scoring vulnerabilities along with half of all the 10 Critical Remote Code Execution vulnerabilities being addressed.

More Work to be Done

Lastly, some minor calls to note that this Patch Tuesday includes SQL Server as that is an atypical family covered during Patch Tuesdays and, arguably more notable, is a reminder that Adobe Flash has officially reached end-of-life and would've been actively removed from all browsers via Windows Update (already).

Summary Tables

Here are this month's patched vulnerabilities split by the product family.

Azure Vulnerabilities

CVEVulnerability TitleExploitedDisclosedCVSS3FAQ?
CVE-2021-1677Azure Active Directory Pod Identity Spoofing VulnerabilityNoNo5.5Yes

Browser Vulnerabilities

CVEVulnerability TitleExploitedDisclosedCVSS3FAQ?
CVE-2021-1705Microsoft Edge (HTML-based) Memory Corruption VulnerabilityNoNo4.2No

Developer Tools Vulnerabilities

cveVulnerability TitleExploitedDisclosedCVSS3FAQ?
CVE-2020-26870Visual Studio Remote Code Execution VulnerabilityNoNo7Yes
CVE-2021-1725Bot Framework SDK Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-1723ASP.NET Core and Visual Studio Denial of Service VulnerabilityNoNo7.5No

Developer Tools Windows Vulnerabilities

CVEVulnerability TitleExploitedDisclosedCVSS3FAQ?
CVE-2021-1651Diagnostics Hub Standard Collector Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1680Diagnostics Hub Standard Collector Elevation of Privilege VulnerabilityNoNo7.8No

Microsoft Office Vulnerabilities

CVEtitleExploitedDisclosedCVSS3FAQ?
CVE-2021-1715Microsoft Word Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-1716Microsoft Word Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-1641Microsoft SharePoint Spoofing VulnerabilityNoNo4.6No
CVE-2021-1717Microsoft SharePoint Spoofing VulnerabilityNoNo4.6No
CVE-2021-1718Microsoft SharePoint Server Tampering VulnerabilityNoNo8No
CVE-2021-1707Microsoft SharePoint Server Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2021-1712Microsoft SharePoint Elevation of Privilege VulnerabilityNoNo8No
CVE-2021-1719Microsoft SharePoint Elevation of Privilege VulnerabilityNoNo8No
CVE-2021-1711Microsoft Office Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-1713Microsoft Excel Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-1714Microsoft Excel Remote Code Execution VulnerabilityNoNo7.8Yes

SQL Server Vulnerabilities

CVEtitleExploitedDisclosedCVSS3FAQ?
CVE-2021-1636Microsoft SQL Elevation of Privilege VulnerabilityNoNo8.8Yes

System Center Vulnerabilities

CVEtitleExploitedDisclosedCVSS3FAQ?
CVE-2021-1647Microsoft Defender Remote Code Execution VulnerabilityYesNo7.8Yes

Windows Vulnerabilities

CVEtitleExploitedDisclosedCVSS3FAQ?
CVE-2021-1681Windows WalletService Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1686Windows WalletService Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1687Windows WalletService Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1690Windows WalletService Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1646Windows WLAN Service Elevation of Privilege VulnerabilityNoNo6.6No
CVE-2021-1650Windows Runtime C++ Template Library Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1663Windows Projected File System FS Filter Driver Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-1670Windows Projected File System FS Filter Driver Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-1672Windows Projected File System FS Filter Driver Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-1689Windows Multipoint Management Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1682Windows Kernel Elevation of Privilege VulnerabilityNoNo7No
CVE-2021-1697Windows InstallService Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1662Windows Event Tracing Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1703Windows Event Logging Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1645Windows Docker Information Disclosure VulnerabilityNoNo5Yes
CVE-2021-1637Windows DNS Query Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-1638Windows Bluetooth Security Feature Bypass VulnerabilityNoNo7.7No
CVE-2021-1683Windows Bluetooth Security Feature Bypass VulnerabilityNoNo5No
CVE-2021-1684Windows Bluetooth Security Feature Bypass VulnerabilityNoNo5No
CVE-2021-1642Windows AppX Deployment Extensions Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1685Windows AppX Deployment Extensions Elevation of Privilege VulnerabilityNoNo7.3No
CVE-2021-1648Microsoft splwow64 Elevation of Privilege VulnerabilityNoYes7.8Yes
CVE-2021-1710Microsoft Windows Media Foundation Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-1691Hyper-V Denial of Service VulnerabilityNoNo7.7No
CVE-2021-1692Hyper-V Denial of Service VulnerabilityNoNo7.7No
CVE-2021-1643HEVC Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-1644HEVC Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes

Windows Apps Vulnerabilities

CVEtitleExploitedDisclosedCVSS3FAQ?
CVE-2021-1669Windows Remote Desktop Security Feature Bypass VulnerabilityNoNo8.8Yes

Windows ESU Vulnerabilities

CVEtitleExploitedDisclosedCVSS3FAQ?
CVE-2021-1709Windows Win32k Elevation of Privilege VulnerabilityNoNo7No
CVE-2021-1694Windows Update Stack Elevation of Privilege VulnerabilityNoNo7.5Yes
CVE-2021-1702Windows Remote Procedure Call Runtime Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1674Windows Remote Desktop Protocol Core Security Feature Bypass VulnerabilityNoNo8.8No
CVE-2021-1695Windows Print Spooler Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1676Windows NT Lan Manager Datagram Receiver Driver Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-1706Windows LUAFV Elevation of Privilege VulnerabilityNoNo7.3No
CVE-2021-1661Windows Installer Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1704Windows Hyper-V Elevation of Privilege VulnerabilityNoNo7.3No
CVE-2021-1696Windows Graphics Component Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-1708Windows GDI+ Information Disclosure VulnerabilityNoNo5.7Yes
CVE-2021-1657Windows Fax Compose Form Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-1679Windows CryptoAPI Denial of Service VulnerabilityNoNo6.5No
CVE-2021-1652Windows CSC Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1653Windows CSC Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1654Windows CSC Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1655Windows CSC Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1659Windows CSC Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1688Windows CSC Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1693Windows CSC Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-1699Windows (modem.sys) Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-1656TPM Device Driver Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-1658Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-1660Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-1666Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-1667Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-1673Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-1664Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-1671Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-1700Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-1701Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8No
CVE-2021-1678NTLM Security Feature Bypass VulnerabilityNoNo4.3No
CVE-2021-1668Microsoft DTV-DVD Video Decoder Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-1665GDI+ Remote Code Execution VulnerabilityNoNo7.8No
CVE-2021-1649Active Template Library Elevation of Privilege VulnerabilityNoNo7.8No

Summary Graphs

output_18_2.pngoutput_25_1.pngoutput_26_1.pngoutput_20_2.png

Note: Graph data is reflective of data presented by Microsoft's CVRF at the time of writing.

Related blog posts