Initiatives for
As the national authority for Cybersecurity the CCB has developed several initiatives for specific publics which are presented here.
Reference:
Advisory #2021-022
Version:
1.0
Affected software:
Etc...
Microsoft Azure
Microsoft Exchange Server
Microsoft Windows 10
Microsoft Windows Server 2019
Type:
Various
CVE/CVSS:
67 vulnerabilities, of which:
Multiple vulnerabilities in Microsoft products, posing a range of risks. Some vulnerabilities may crash the targeted device, while others can be used to take complete control over the device.
This month’s Patch Tuesday includes several severe vulnerabilities for a wide range of Microsoft products, including vulnerabilities in Microsoft Exchange, that can be used to run arbitrary code on the vulnerable device. These vulnerabilities are marked as “Critical” by Microsoft and require urgent attention.
Several vulnerabilities, including critical ones, are applicable for both Microsoft Server and Workstation.
Other vulnerabilities are also present, ranging from "Moderate" to “Critical”. In total, Microsoft released patches for 67 vulnerabilities. 6 of these vulnerabilities have the highest severity (Critical) and 1 is actively being exploited.
Microsoft has released multiple patches for vulnerabilities covering a range of their products. These monthly releases are called “Patch Tuesday”, and contain security fixes for Microsoft devices and software. This month’s release covers 67 vulnerabilities, 6 of which are considered zero-day vulnerabilities. One of these vulnerabilities is also actively exploited in malware distribution campaigns. Due to the high severity and risk of these vulnerabilities, urgent patching is advised.
CERT.be recommends installing updates for vulnerable devices with the highest priority. Updates can be done through Microsoft’s Update panel, and/or through their Security Advisory website.