Service Notices
Microsoft Releases June 2021 Security Updates
Jun 10, 2021 GMT+08:00
I. Overview
Microsoft recently released its monthly set of security updates. 50 vulnerabilities are disclosed, among which 5 are rated important. Attackers can exploit these vulnerabilities to perform remote code execution, escalate privileges, and leak sensitive information. The following software is affected: Microsoft Windows, Windows Server, Edge, and SharePoint. If you are a Microsoft user, check your system and implement timely security hardening.
For details, visit the Microsoft official website:
https://msrc.microsoft.com/update-guide/releaseNote/2021-Jun
The following 0-day vulnerabilities have been exploited by attackers. Install patches in a timely manner to prevent attacks.
CVE-2021-31955: Windows Kernel Information Disclosure Vulnerability
CVE-2021-31956: Windows NTFS Elevation of Privilege Vulnerability
CVE-2021-33739: Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2021-33742: Windows MSHTML Platform Remote Code Execution Vulnerability
CVE-2021-31199: Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
CVE-2021-31201: Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
II. Severity
Severity: important
(Severity: low, moderate, important, and critical)
III. Affected Products
Microsoft Windows, Windows Server, Edge, SharePoint, etc.
IV. Vulnerability Details
CVE ID | Vulnerability Name | Severity | Affected Product |
CVE-2021-31985 | Microsoft Defender Remote Code Execution Vulnerability | Important | Microsoft Malware Protection Engine |
CVE-2021-31959 | Scripting Engine Memory Corruption Vulnerability | Important | Windows 10, Windows 8.1/RT 8.1, Windows 7, Windows Server 2008 R2/2012/2012 R2/2016/2019 |
CVE-2021-31967 | VP9 Video Extension Remote Code Execution Vulnerability | Important | VP9 Video Extensions |
CVE-2021-31963 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | Microsoft SharePoint Foundation 2013, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2013/2016 |
CVE-2021-33742 | Windows MSHTML platform remote code execution vulnerability | Important | Windows 10, Windows 8.1/RT 8.1, Windows 7, Windows Server 2008/2008 R2/2012/2012 R2/2016/2019 |
(Note: Vulnerabilities listed above are important ones. For more information, refer to the official website of Microsoft.)
V. Security Recommendations
1. Use Windows Update or download patches from the following address to fix the vulnerabilities:
https://msrc.microsoft.com/update-guide
2. Back up data remotely to protect your data.
Note: Before fixing vulnerabilities, back up your files and conduct a thorough test.