=========================================================================== ZMCIRT Vulnerability Bulletin ZMC-2021.09.15.1700 Microsoft Office Products & Services and Web App Products: Multiple vulnerabilities 15th Sep 2021 =========================================================================== Product: Microsoft 365 Apps for Enterprise Microsoft Excel Microsoft Office Microsoft Office Online Server Microsoft Office Web Apps Server Microsoft SharePoint Enterprise Server Microsoft SharePoint Foundation Microsoft SharePoint Server Operating System: Windows Mac OS Impact/Access: Execute Arbitrary Code/Commands -- Existing Account Provide Misleading Information -- Existing Account Resolution: Patch/Upgrade CVE Names: CVE-2021-38660 CVE-2021-38659 CVE-2021-38658 CVE-2021-38657 CVE-2021-38656 CVE-2021-38655 CVE-2021-38654 CVE-2021-38653 CVE-2021-38652 CVE-2021-38651 CVE-2021-38650 CVE-2021-38646 OVERVIEW Microsoft has released its monthly security patch update for the month of September 2021. This update resolves 12 vulnerabilities across the following product(s): [1] Microsoft 365 Apps for Enterprise for 32-bit Systems Microsoft 365 Apps for Enterprise for 64-bit Systems Microsoft Excel 2013 RT Service Pack 1 Microsoft Excel 2013 Service Pack 1 (32-bit editions) Microsoft Excel 2013 Service Pack 1 (64-bit editions) Microsoft Excel 2016 (32-bit edition) Microsoft Excel 2016 (64-bit edition) Microsoft Office 2013 RT Service Pack 1 Microsoft Office 2013 Service Pack 1 (32-bit editions) Microsoft Office 2013 Service Pack 1 (64-bit editions) Microsoft Office 2016 (32-bit edition) Microsoft Office 2016 (64-bit edition) Microsoft Office 2019 for 32-bit editions Microsoft Office 2019 for 64-bit editions Microsoft Office 2019 for Mac Microsoft Office Online Server Microsoft Office Web Apps Server 2013 Service Pack 1 Microsoft SharePoint Enterprise Server 2016 Microsoft SharePoint Foundation 2013 Service Pack 1 Microsoft SharePoint Server 2019 IMPACT Microsoft has given the following details regarding these vulnerabilities. Details Impact Severity CVE-2021-38646 Remote Code Execution Important CVE-2021-38650 Spoofing Important CVE-2021-38651 Spoofing Important CVE-2021-38652 Spoofing Important CVE-2021-38653 Remote Code Execution Important CVE-2021-38654 Remote Code Execution Important CVE-2021-38655 Remote Code Execution Important CVE-2021-38656 Remote Code Execution Important CVE-2021-38657 Remote Code Execution Important CVE-2021-38658 Remote Code Execution Important CVE-2021-38659 Remote Code Execution Important CVE-2021-38660 Remote Code Execution Important MITIGATION Microsoft recommends updating the software with the version made available on the Microsoft Update Catalogue for the following Knowledge Base articles. [1]. KB4484103, KB4484108, KB5001958, KB5001997, KB5001999 KB5002003, KB5002005, KB5002007, KB5002009, KB5002014 KB5002018, KB5002020, KB5002024 REFERENCES [1] Microsoft Security Update Guidance https://portal.msrc.microsoft.com/en-us/security-guidance ZMCIRT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. ZMCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Internet Email: report@cirt.zm Telephone: 7070 ZMCIRT personnel answer during Zambian business hours which are 8am to 5pm. On call after hours for member emergencies only. ===========================================================================
Copyright @2023 ZAMBIA CIRT