Microsoft Updates
3881Warning Date
Severity Level
Warning Number
Target Sector
15 December, 2021
● Critical
2021-4073
All
Description:
Microsoft has released security updates to address several vulnerabilities in the following products:
- Windows Media
- Microsoft Windows Codecs Library
- Microsoft Defender for IoT
- Internet Storage Name Service
- Microsoft Local Security Authority Server (lsasrv)
- Windows Encrypting File System (EFS)
- Windows DirectX
- Microsoft Message Queuing
- Windows Remote Access Connection Manager
- Windows Common Log File System Driver
- Azure Bot Framework SDK
- Windows Storage Spaces Controller
- Windows SymCrypt
- Windows NTFS
- Windows Event Tracing
- Remote Desktop Client
- Role: Windows Fax Service
- Windows Storage
- Windows Update Stack
- Windows Kernel
- Windows Digital TV Tuner
- Role: Windows Hyper-V
- Windows TCP/IP
- Office Developer Platform
- Microsoft Office
- ASP.NET Core & Visual Studio
- Visual Studio Code
- Microsoft Devices
- Windows Print Spooler Components
- Windows Mobile Device Management
- Windows Installer
- Microsoft PowerShell
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Spoofing
- Disclosure of information
- Privilege escalation
- Remote code execution
Best practice and Recommendations:
The CERT team encourages users to review Microsoft security advisory and apply the necessary updates:
Update instructions: