{"id":259660,"date":"2021-11-21T00:52:11","date_gmt":"2021-11-20T23:52:11","guid":{"rendered":"https:\/\/www.borncity.com\/blog\/?p=259660"},"modified":"2021-11-21T01:19:18","modified_gmt":"2021-11-21T00:19:18","slug":"windows-10-elevation-of-privilege-sicherheitslcken-im-update-assistant-und-weitere-revisionen","status":"publish","type":"post","link":"https:\/\/borncity.com\/blog\/2021\/11\/21\/windows-10-elevation-of-privilege-sicherheitslcken-im-update-assistant-und-weitere-revisionen\/","title":{"rendered":"Windows 10: Elevation of Privilege Sicherheitsl&uuml;cken im Update Assistant und weitere Revisionen"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" title=\"Windows\" src=\"https:\/\/borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Windows-klein.jpg\" alt=\"Windows\" width=\"200\" align=\"left\" \/>[<a href=\"https:\/\/borncity.com\/win\/2021\/11\/21\/windows-10-elevation-of-privilege-vulnerabilities-in-update-assistant-and-cve-revisions\/\" target=\"_blank\" rel=\"noopener\">English<\/a>]Kurzer Nachtrag von dieser Woche. Microsoft hat zum 16. November 2021 eine Sicherheitswarnung herausgegeben. Es wird dort mitgeteilt, das der Windows 10 Update Assistant Elevation of Privilege Sicherheitsl\u00fccken aufweist. Konkret geht es um zwei Schwachstellen CVE-2021-42297 und CVE-2021-43211. Zudem gab es einige Update-Revisionen zu Schwachstellen in Excel etc.<\/p>\n<p><!--more--><\/p>\n<h3>Elevation of Privilege im Windows 10 Update Assistant<\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg08.met.vgwort.de\/na\/0ba6afe81b2f490586d95c0893f51a27\" alt=\"\" width=\"1\" height=\"1\" \/>Im Windows 10 Update Assistant Elevation of Privilege wurden zwei Schwachstellen gefunden, die eine Ausweitung der Rechte erm\u00f6glichen. Hier die Sicherheitsmeldung:<\/p>\n<p>&#8211; <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-42297\" target=\"_blank\" rel=\"noopener\">CVE-2021-42297<\/a> | Windows 10 Update Assistant Elevation of Privilege Vulnerability<br \/>\n&#8211; Version: 1.0<br \/>\n&#8211; Reason for Revision: Information published.<br \/>\n&#8211; Originally posted: November 16, 2021<br \/>\n&#8211; Updated: N\/A<br \/>\n&#8211; Aggregate CVE Severity Rating: Important<\/p>\n<p>&#8211; <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-43211\" target=\"_blank\" rel=\"noopener\">CVE-2021-43211<\/a> | Windows 10 Update Assistant Elevation of Privilege Vulnerability<br \/>\n&#8211; Version: 1.0<br \/>\n&#8211; Reason for Revision: Information published.<br \/>\n&#8211; Originally posted: November 16, 2021<br \/>\n&#8211; Updated: N\/A<br \/>\n&#8211; Aggregate CVE Severity Rating: Important<\/p>\n<p>Ein Angreifer w\u00e4re \u00fcber beide Schwachstellen nur in der Lage, gezielt Dateien auf einem System zu l\u00f6schen. Er w\u00fcrde keine Berechtigung zum Anzeigen oder \u00c4ndern von Dateiinhalten erhalten. Microsoft stuft die Ausnutzbarkeit dieser Schwachstelle, die von mehreren Sicherheitsforschern gemeldet wurden, als niedrig ein. Microsoft hat aber den Windows 10 Update Assistant aktualisiert und bietet die revidierte Version auf der <a href=\"https:\/\/www.microsoft.com\/en-us\/software-download\/windows10\" target=\"_blank\" rel=\"noopener\">Windows 10-Download-Seite<\/a> an.<\/p>\n<h2>Weitere CVE-Revisionen<\/h2>\n<p>Zudem wurden an fr\u00fcheren Sicherheitswarnungen einige Revisionen in der Beschreibung\/Einstufung vorgenommen. Hier die betreffenden Informationen:<\/p>\n<p>* CVE-2021-40442<br \/>\n* CVE-2021-42292<br \/>\n* CVE-2021-42321<\/p>\n<p>&#8211; <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-40442\" target=\"_blank\" rel=\"noopener\">CVE-2021-40442<\/a> | Microsoft Excel Remote Code Execution Vulnerability<br \/>\n&#8211; Version: 2.0<br \/>\n&#8211; Reason for Revision: Microsoft is announcing the availability of the security updates<br \/>\nfor Microsoft Office for Mac. Customers running affected Mac software should install<br \/>\nthe update for their product to be protected from this vulnerability. Customers<br \/>\nrunning other Microsoft Office software do not need to take any action. See the<br \/>\nRelease Notes for more information and download links.<br \/>\n&#8211; Originally posted: November 9, 2021<br \/>\n&#8211; Updated: November 16, 2021<br \/>\n&#8211; Aggregate CVE Severity Rating: Important<\/p>\n<p>&#8211; <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-42292\" target=\"_blank\" rel=\"noopener\">CVE-2021-42292<\/a> | Microsoft Excel Security Feature Bypass Vulnerability<br \/>\n&#8211; Version: 2.0<br \/>\n&#8211; Reason for Revision: Microsoft is announcing the availability of the security updates<br \/>\nfor Microsoft Office for Mac. Customers running affected Mac software should install<br \/>\nthe update for their product to be protected from this vulnerability. Customers<br \/>\nrunning other Microsoft Office software do not need to take any action. See the<br \/>\nRelease Notes for more information and download links.<br \/>\n&#8211; Originally posted: November 9, 2021<br \/>\n&#8211; Updated: November 16, 2021<br \/>\n&#8211; Aggregate CVE Severity Rating: Important<\/p>\n<p>&#8211; <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-42321\" target=\"_blank\" rel=\"noopener\">CVE-2021-42321<\/a> | Microsoft Exchange Server Remote Code Execution Vulnerability<br \/>\n&#8211; Version: 1.1<br \/>\n&#8211; Reason for Revision: Added Microsoft Exchange Server 2013 to the Security Updates<br \/>\ntable. Customers that are using this version of Microsoft Exchange should install<br \/>\nthis update to be protected from this vulnerability.<br \/>\n&#8211; Originally posted: November 9, 2021<br \/>\n&#8211; Updated: November 16, 2021<br \/>\n&#8211; Aggregate CVE Severity Rating: Important<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[English]Kurzer Nachtrag von dieser Woche. Microsoft hat zum 16. November 2021 eine Sicherheitswarnung herausgegeben. Es wird dort mitgeteilt, das der Windows 10 Update Assistant Elevation of Privilege Sicherheitsl\u00fccken aufweist. Konkret geht es um zwei Schwachstellen CVE-2021-42297 und CVE-2021-43211. Zudem gab &hellip; <a href=\"https:\/\/borncity.com\/blog\/2021\/11\/21\/windows-10-elevation-of-privilege-sicherheitslcken-im-update-assistant-und-weitere-revisionen\/\">Weiterlesen <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[426,185,3694],"tags":[4328,4315,4378],"class_list":["post-259660","post","type-post","status-publish","format-standard","hentry","category-sicherheit","category-update","category-windows-10","tag-sicherheit","tag-update","tag-windows-10"],"_links":{"self":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/259660","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/comments?post=259660"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/259660\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/media?parent=259660"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/categories?post=259660"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/tags?post=259660"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}