{"id":22226,"date":"2021-11-21T01:17:40","date_gmt":"2021-11-21T00:17:40","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=22226"},"modified":"2021-11-21T01:17:40","modified_gmt":"2021-11-21T00:17:40","slug":"windows-10-elevation-of-privilege-vulnerabilities-in-update-assistant-and-cve-revisions","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2021\/11\/21\/windows-10-elevation-of-privilege-vulnerabilities-in-update-assistant-and-cve-revisions\/","title":{"rendered":"Windows 10: Elevation of Privilege Vulnerabilities in Update Assistant; and CVE Revisions"},"content":{"rendered":"<p><img decoding=\"async\" title=\"Windows\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" alt=\"Windows\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Windows-klein.jpg\" width=\"200\" align=\"left\">[<a href=\"https:\/\/www.borncity.com\/blog\/2021\/11\/21\/windows-10-elevation-of-privilege-sicherheitslcken-im-update-assistant-und-weitere-revisionen\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Short addendum from this week. Microsoft has issued a security warning for November 16, 2021. It states that the Windows 10 Update Assistant Elevation of Privilege has security vulnerabilities. Specifically, it is about two vulnerabilities CVE-2021-42297 and CVE-2021-43211. In addition, there were some update revisions to vulnerabilities in Excel, etc.<\/p>\n<p><!--more--><\/p>\n<h3>Elevation of Privilege in Windows 10 Update Assistant <\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg08.met.vgwort.de\/na\/0ba6afe81b2f490586d95c0893f51a27\" width=\"1\" height=\"1\">Two vulnerabilities were found in the Windows 10&nbsp; Update Assistant Elevation of Privilege. Here is the security advisory:<\/p>\n<p>&#8211; <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-42297\" target=\"_blank\" rel=\"noopener\">CVE-2021-42297<\/a> | Windows 10 Update Assistant Elevation of Privilege Vulnerability<br \/>&#8211; Version: 1.0<br \/>&#8211; Reason for Revision: Information published.<br \/>&#8211; Originally posted: November 16, 2021<br \/>&#8211; Updated: N\/A<br \/>&#8211; Aggregate CVE Severity Rating: Important<\/p>\n<p>&#8211; <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-43211\" target=\"_blank\" rel=\"noopener\">CVE-2021-43211<\/a> | Windows 10 Update Assistant Elevation of Privilege Vulnerability<br \/>&#8211; Version: 1.0<br \/>&#8211; Reason for Revision: Information published.<br \/>&#8211; Originally posted: November 16, 2021<br \/>&#8211; Updated: N\/A<br \/>&#8211; Aggregate CVE Severity Rating: Important<\/p>\n<p>An attacker would only be able to delete targeted files on a system via both vulnerabilities. He would not gain permission to view or modify file contents. Microsoft rates the exploitability of this vulnerability, which has been reported by several security researchers, as low. However, Microsoft has updated the Windows 10 Update Assistant and is offering the revised version on the <a href=\"https:\/\/www.microsoft.com\/en-us\/software-download\/windows10\" target=\"_blank\" rel=\"noopener\">Windows 10 download page<\/a>. <\/p>\n<h2>More CVE revisions <\/h2>\n<p>In addition, some revisions have been made to the description\/classification of previous security alerts. Here is the information in question:<\/p>\n<p>* CVE-2021-40442<br \/>* CVE-2021-42292<br \/>* CVE-2021-42321<\/p>\n<p>&#8211; <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-40442\" target=\"_blank\" rel=\"noopener\">CVE-2021-40442<\/a> | Microsoft Excel Remote Code Execution Vulnerability<br \/>&#8211; Version: 2.0<br \/>&#8211; Reason for Revision: Microsoft is announcing the availability of the security updates <br \/>&nbsp;&nbsp; for Microsoft Office for Mac. Customers running affected Mac software should install<br \/>&nbsp;&nbsp; the update for their product to be protected from this vulnerability. Customers<br \/>&nbsp;&nbsp; running other Microsoft Office software do not need to take any action. See the<br \/>&nbsp;&nbsp; Release Notes for more information and download links.<br \/>&#8211; Originally posted: November 9, 2021<br \/>&#8211; Updated: November 16, 2021<br \/>&#8211; Aggregate CVE Severity Rating: Important<\/p>\n<p>&#8211; <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-42292\" target=\"_blank\" rel=\"noopener\">CVE-2021-42292<\/a> | Microsoft Excel Security Feature Bypass Vulnerability<br \/>&#8211; Version: 2.0<br \/>&#8211; Reason for Revision: Microsoft is announcing the availability of the security updates <br \/>&nbsp;&nbsp; for Microsoft Office for Mac. Customers running affected Mac software should install<br \/>&nbsp;&nbsp; the update for their product to be protected from this vulnerability. Customers<br \/>&nbsp;&nbsp; running other Microsoft Office software do not need to take any action. See the<br \/>&nbsp;&nbsp; Release Notes for more information and download links.<br \/>&#8211; Originally posted: November 9, 2021<br \/>&#8211; Updated: November 16, 2021<br \/>&#8211; Aggregate CVE Severity Rating: Important<\/p>\n<p>&#8211; <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-42321\" target=\"_blank\" rel=\"noopener\">CVE-2021-42321<\/a> | Microsoft Exchange Server Remote Code Execution Vulnerability<br \/>&#8211; Version: 1.1<br \/>&#8211; Reason for Revision: Added Microsoft Exchange Server 2013 to the Security Updates<br \/>&nbsp;&nbsp; table. Customers that are using this version of Microsoft Exchange should install<br \/>&nbsp;&nbsp; this update to be protected from this vulnerability.<br \/>&#8211; Originally posted: November 9, 2021<br \/>&#8211; Updated: November 16, 2021<br \/>&#8211; Aggregate CVE Severity Rating: Important<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Short addendum from this week. Microsoft has issued a security warning for November 16, 2021. It states that the Windows 10 Update Assistant Elevation of Privilege has security vulnerabilities. Specifically, it is about two vulnerabilities CVE-2021-42297 and CVE-2021-43211. In addition, &hellip; <a href=\"https:\/\/borncity.com\/win\/2021\/11\/21\/windows-10-elevation-of-privilege-vulnerabilities-in-update-assistant-and-cve-revisions\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,2],"tags":[69,195,76],"class_list":["post-22226","post","type-post","status-publish","format-standard","hentry","category-security","category-windows","tag-security","tag-update","tag-windows-10"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/22226","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=22226"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/22226\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=22226"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=22226"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=22226"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}