Microsoft patches 66 vulnerabilities in September update
Summary
Microsoft has pushed fixes for a total of 66 common vulnerabilities and exposures (CVEs), three critical and one moderate in severity, as well as the previously disclosed CVE-2021-40444 zero-day, in its September 2021 Patch Tuesday update. CVE-2021-40444 is a remote code execution vulnerability in Microsoft MSHTML, a component used in Internet Explorer and Office, and a workaround to address it was made available last week. “An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document or a rich text file that hosts the browser rendering engine. “For the last few months, we have seen a steady stream of patches for flaws in Windows Print Spooler following the disclosure of PrintNightmare in July,” said Tenable staff research engineer Satnam Narang. Kevin Breen, Immersive Labs’ director of cyber threat research, said: “This cycle, we’ve seen 25 vulnerabilities that have been patched in Chrome and ported over to Microsoft’s Chromium-based Edge.