Service Notices

All Notices > Security Notices > Microsoft Releases June 2021 Security Updates

Microsoft Releases June 2021 Security Updates

Jun 10, 2021 GMT+08:00

I. Overview

Microsoft recently released its monthly set of security updates. 50 vulnerabilities are disclosed, among which 5 are rated important. Attackers can exploit these vulnerabilities to perform remote code execution, escalate privileges, and leak sensitive information. The following software is affected: Microsoft Windows, Windows Server, Edge, and SharePoint. If you are a Microsoft user, check your system and implement timely security hardening.

For details, visit the Microsoft official website:

https://msrc.microsoft.com/update-guide/releaseNote/2021-Jun

The following 0-day vulnerabilities have been exploited by attackers. Install patches in a timely manner to prevent attacks.

CVE-2021-31955: Windows Kernel Information Disclosure Vulnerability

CVE-2021-31956: Windows NTFS Elevation of Privilege Vulnerability

CVE-2021-33739: Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2021-33742: Windows MSHTML Platform Remote Code Execution Vulnerability

CVE-2021-31199: Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

CVE-2021-31201: Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

II. Severity

Severity: important

(Severity: low, moderate, important, and critical)

III. Affected Products

Microsoft Windows, Windows Server, Edge, SharePoint, etc.

IV. Vulnerability Details

CVE ID

Vulnerability Name

Severity

Affected Product

CVE-2021-31985

Microsoft Defender Remote Code Execution Vulnerability

Important

Microsoft Malware Protection Engine

CVE-2021-31959

Scripting Engine Memory Corruption Vulnerability

Important

Windows 10, Windows 8.1/RT 8.1, Windows 7, Windows Server 2008 R2/2012/2012 R2/2016/2019

CVE-2021-31967

VP9 Video Extension Remote Code Execution Vulnerability

Important

VP9 Video Extensions

CVE-2021-31963

Microsoft SharePoint Server Remote Code Execution Vulnerability

Important

Microsoft SharePoint Foundation 2013, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2013/2016

CVE-2021-33742

Windows MSHTML platform remote code execution vulnerability

Important

Windows 10, Windows 8.1/RT 8.1, Windows 7, Windows Server 2008/2008 R2/2012/2012 R2/2016/2019

(Note: Vulnerabilities listed above are important ones. For more information, refer to the official website of Microsoft.)

V. Security Recommendations

1. Use Windows Update or download patches from the following address to fix the vulnerabilities:

https://msrc.microsoft.com/update-guide

2. Back up data remotely to protect your data.

Note: Before fixing vulnerabilities, back up your files and conduct a thorough test.