Detection and Response

Patch Tuesday - June 2021

|Last updated on Jun 9, 2021|1 min read
LinkedInFacebookX
Patch Tuesday - June 2021

It is another low volume Patch Tuesday this month as Microsoft releases fixes for 50 vulnerabilities. This should not diminish the importance of speedily applying the updates. 6 of the vulnerabilities being patched this month are 0-days under active exploitation (CVE-2021-31955, CVE-2021-31956, CVE-2021-33739, CVE-2021-33742, CVE-2021-31199, and CVE-2021-31201). These patches should be given immediate priority. Luckily they can all be addressed by normal operating system patches and should not require additional manual intervention. Additionally, Enterprises should take action on CVE-2021-31962 if they use Kerberos in their environment as it may allow an attacker to bypass Kerberos authentication altogether.

Windows MSHTML Platform Remote Code Execution Vulnerability (CVE-2021-33742)

This is the only 0-day vulnerability this month which results in a remote code execution. The vulnerability lies within the MSHTML platform which is used by Internet Explorer 11 and Edge Legacy. While these two products are no longer fully supported (Edge Legacy is end of life and IE 11 is no longer supported on certain platforms) the underlying HTML libraries continue to be updated as other applications can make use of it. Further details for this vulnerability will be published by Google's Threat Analysis Group within the next 30 days.

Kerberos AppContainer Security Feature Bypass Vulnerability (CVE-2021-31962)

While this vulnerability has not been exploited in the wild yet, it would be a rather juicy target for exploit developers. Were this to be exploited it may allow a complete bypass of Kerberos authentication, allowing a connection without a password. Kerberos is generally used in Enterprise environments and as such sysadmins should patch this if they are leveraging the strong cryptography authentication mechanism.

Multiple Elevation of Privilege 0-days

CVE-2021-31955, CVE-2021-31956, CVE-2021-33739, CVE-2021-31199, and CVE-2021-31201


The rest of the 0-days this month can result in elevation of privilege. These vulnerabilities are often chained with other vulnerabilities in order to achieve code execution as an Administrator. Luckily for defenders, these vulnerabilities are simply patched using the traditional update methods.

Summary Tables

Here are this month's patched vulnerabilities split by the product family.

Apps Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-31945Paint 3D Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-31946Paint 3D Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-31983Paint 3D Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-31980Microsoft Intune Management Extension Remote Code Execution VulnerabilityNoNo8.1Yes
CVE-2021-319423D Viewer Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-319433D Viewer Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-319443D Viewer Information Disclosure VulnerabilityNoNo5Yes

Browser Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-33741Microsoft Edge (Chromium-based) Elevation of Privilege VulnerabilityNoNo8.2Yes

Developer Tools Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-31938Microsoft VsCode Kubernetes Tools Extension Elevation of Privilege VulnerabilityNoNo7.3Yes
CVE-2021-31957.NET Core and Visual Studio Denial of Service VulnerabilityNoNo5.9No

ESU Windows Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-31968Windows Remote Desktop Services Denial of Service VulnerabilityNoYes7.5No
CVE-2021-1675Windows Print Spooler Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-31958Windows NTLM Elevation of Privilege VulnerabilityNoNo7.5Yes
CVE-2021-31956Windows NTFS Elevation of Privilege VulnerabilityYesNo7.8Yes
CVE-2021-33742Windows MSHTML Platform Remote Code Execution VulnerabilityYesNo7.5Yes
CVE-2021-31971Windows HTML Platform Security Feature Bypass VulnerabilityNoNo6.8Yes
CVE-2021-31973Windows GPSVC Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-31953Windows Filter Manager Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-26414Windows DCOM Server Security Feature BypassNoNo4.8Yes
CVE-2021-31954Windows Common Log File System Driver Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-31959Scripting Engine Memory Corruption VulnerabilityNoNo6.4Yes
CVE-2021-31199Microsoft Enhanced Cryptographic Provider Elevation of Privilege VulnerabilityYesNo5.2Yes
CVE-2021-31201Microsoft Enhanced Cryptographic Provider Elevation of Privilege VulnerabilityYesNo5.2Yes
CVE-2021-31962Kerberos AppContainer Security Feature Bypass VulnerabilityNoNo9.4Yes

Microsoft Office Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-31964Microsoft SharePoint Server Spoofing VulnerabilityNoNo7.6No
CVE-2021-31948Microsoft SharePoint Server Spoofing VulnerabilityNoNo7.6No
CVE-2021-31950Microsoft SharePoint Server Spoofing VulnerabilityNoNo7.6No
CVE-2021-31966Microsoft SharePoint Server Remote Code Execution VulnerabilityNoNo7.2No
CVE-2021-31963Microsoft SharePoint Server Remote Code Execution VulnerabilityNoNo7.1No
CVE-2021-26420Microsoft SharePoint Server Remote Code Execution VulnerabilityNoNo7.1No
CVE-2021-31965Microsoft SharePoint Server Information Disclosure VulnerabilityNoNo5.7Yes
CVE-2021-31949Microsoft Outlook Remote Code Execution VulnerabilityNoNo6.7Yes
CVE-2021-31940Microsoft Office Graphics Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-31941Microsoft Office Graphics Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-31939Microsoft Excel Remote Code Execution VulnerabilityNoNo7.8Yes

System Center Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-31985Microsoft Defender Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-31978Microsoft Defender Denial of Service VulnerabilityNoNo5.5Yes

Windows Vulnerabilities

CVETitleExploitedDisclosedCVSS3FAQ
CVE-2021-31970Windows TCP/IP Driver Security Feature Bypass VulnerabilityNoNo5.5No
CVE-2021-31952Windows Kernel-Mode Driver Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-31955Windows Kernel Information Disclosure VulnerabilityYesNo5.5Yes
CVE-2021-31951Windows Kernel Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-31977Windows Hyper-V Denial of Service VulnerabilityNoNo8.6Yes
CVE-2021-31969Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2021-31960Windows Bind Filter Driver Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2021-31967VP9 Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2021-31975Server for NFS Information Disclosure VulnerabilityNoNo7.5Yes
CVE-2021-31976Server for NFS Information Disclosure VulnerabilityNoNo7.5Yes
CVE-2021-31974Server for NFS Denial of Service VulnerabilityNoNo7.5No
CVE-2021-33739Microsoft DWM Core Library Elevation of Privilege VulnerabilityYesYes8.4Yes
CVE-2021-31972Event Tracing for Windows Information Disclosure VulnerabilityNoNo5.5Yes

Summary Graphs

output_18_2.pngoutput_20_2.pngoutput_25_1.pngoutput_26_1.png

Related blog posts