Microsoft's May Patch Tuesday Brings 55 Critical Security Fixes, Update Now
This entry was posted on May 13, 2021.
Of the 55 fixes coming with this patch, the wormable HTTP protocol-stack vulnerability, denoted by CVE-2021-31166, is the most concerning. This vulnerability has been given a rather high Common Vulnerability Scoring System (CVSS) score at 9.8 out of 10, which means it can be dangerous if used. According to Microsoft Security Response Center (MSRC), this vulnerability can be performed over a network, has low complexity, and has a high impact on the CIA triad, or confidentiality, integrity, and availability. This is the perfect storm for a vulnerability, but thankfully there has not been any known use of this in the wild yet.
Another interesting vulnerability that should get some attention is CVE-2021-26419, which gives even more of a reason to kill off Internet Explorer entirely. The MSRC page for the vulnerability explains that an attacker could “host a specially crafted website that is designed to exploit the vulnerability through Internet Explorer and then convince a user to view the website.” The user accessing the webpage could allow the remote attacker to execute code through Internet Explorer 11.
Besides these two, there are many more fixed vulnerabilities in this update which we did not cover, so perhaps it is time to patch your systems. Before you update, save yourself some future trouble and make a backup just in case something goes awry. We have seen issues in the past with Microsoft patches, but we hope those have been squared away and quality assurance has improved.
As always, hackers are always out there trying to find new vulnerabilities, so getting into the habit of regularly updating is a good thing, even if there are concerns about broken updates. Anyhow, if you have read about another interesting vulnerability that we did not cover, let us know about it in the comments below.