CVE-2021-1648
published 2021-01-12CVE-2021-1648: Microsoft splwow64 Elevation of Privilege Vulnerability
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.23%
65.5th percentile
Microsoft splwow64 Elevation of Privilege Vulnerability
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1607 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1909 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < publication | publication |
| microsoft | windows_8.1 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.0 < publication | publication |
| microsoft | windows_server_2012_r2 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_2019 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < publication | publication |
| msrc | windows_10 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6v5j-ff9r-2442: Microsoft splwow64 Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-1648 [HIGH] CWE-269 GHSA-6v5j-ff9r-2442: Microsoft splwow64 Elevation of Privilege Vulnerability
Microsoft splwow64 Elevation of Privilege Vulnerability
Project0
Déjà vu-lnerability - Project Zero
project_zero·2021-02-01
CVE-2014-9665 Déjà vu-lnerability - Project Zero
A Year in Review of 0-days Exploited In-The-Wild in 2020
Posted by Maddie Stone, Project Zero
2020 was a year full of 0-day exploits. Many of the Internet’s most popular browsers had their moment in the spotlight. Memory corruption is still the name of the game and how the vast majority of detected 0-days are getting in. While we tried new methods of 0-day detection with modest success, 2020 showed us that there is still a long way to go in detecting these 0-day exploits in-the-wild. But what may be the most notable fact is that 25% of the 0-days detected in 2020 are closely related to previously publicly disclosed vulnerabilities. In other words, 1 out of every 4 detected 0-day exploits could potentially have been avoided if a more thorough investigation and patching effort were explor
Project0
Project Zero RCA: CVE-2020-0986: Windows splwow64 Untrusted Pointer Dereference
project_zero·CVSS 7.8
CVE-2020-0986 [HIGH] Project Zero RCA: CVE-2020-0986: Windows splwow64 Untrusted Pointer Dereference
# CVE-2020-0986: Windows splwow64 Untrusted Pointer Dereference
*Maddie Stone, Project Zero (Originally posted on [Project Zero blog](https://googleprojectzero.blogspot.com/p/rca.html) 2020-09-02)*
## The Basics
**Disclosure or Patch Date:**
* 19 May 2020 (ZDI Disclosure)
* 9 June 2020 (Microsoft Advisory/Patch)
* 12 Aug 2020 (Kaspersky blog post about in-the-wild exploitation)
**Product:** Microsoft Windows
**Advisory:**
* ZDI: https://www.zerodayinitiative.com/advisories/ZDI-20-663/
* Microsoft: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0986
* Kaspersky: https://securelist.com/ie-and-windows-zero-day-operation-powerfall/97976/
**Affected Versions:** For Windows 10 1909/1903, [KB4556799](https://support.microsoft.com/en-us/help/4556799/windows-10-u
Microsoft
Microsoft splwow64 Elevation of Privilege Vulnerability
vendor_msrc·2021-01-12·CVSS 7.8
CVE-2021-1648 [HIGH] Microsoft splwow64 Elevation of Privilege Vulnerability
Microsoft splwow64 Elevation of Privilege Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
While this issue is labeled as an elevation of privilege, it can also be exploited to disclose information. The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory.
This CVE is marked as Publicly Disclosed. In what way was it made public?
This issue has been publicly disclosed by Google Project Zero (PZ2096) and the Zero Day Initiative (ZDI-CAN-11349 through 11351).
Windows splwow64: Windows splwow64
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:Yes;Exploited:No;Latest Software Release:Exploitation Less Likely;Older
No detection rules found.
No public exploits indexed.
Trendmicro
January Patch Tuesday Repairs Critical MS Defender RCE Bug
blogs_trendmicro·2021-01-13·CVSS 7.8
[HIGH] January Patch Tuesday Repairs Critical MS Defender RCE Bug
Exploits & Vulnerabilities
# January Patch Tuesday Repairs Critical MS Defender RCE Bug
Microsoft welcomed the first month of 2021 with a total of 83 security updates — which is an uptick from December’s relatively lighter list.
By: Trend Micro
2021/01/13
Read time: ( words)
Save to Folio
Updated on 1/14/2021 7 p.m. PST to include TippingPoint® Next-Generation Intrusion Prevention System (NGIPS) Protection rules.
Microsoft welcomed the first month of 2021 with a total of 83 security updates — which is an uptick from December’s relatively lighter list. The January Patch Tuesday features 10 Critical and 73 Important patches. All of this month’s Critical patches are meant to fix remote code execution (RCE) vulnerabilities among certain Microsoft products, including Microsoft Defender,
Krebs
Microsoft Patch Tuesday, January 2021 Edition
blogs_krebs·2021-01-13·CVSS 8.3
[HIGH] Microsoft Patch Tuesday, January 2021 Edition
Microsoft today released updates to plug more than 80 security holes in its Windows operating systems and other software, including one that is actively being exploited and another which was disclosed prior to today. Ten of the flaws earned Microsoft’s most-dire “critical” rating, meaning they could be exploited by malware or miscreants to seize remote control over unpatched systems with little or no interaction from Windows users.
Most concerning of this month’s batch is probably a critical bug ( CVE-2021-1647 ) in Microsoft’s default anti-malware suite — Windows Defender — that is seeing active exploitation. Microsoft recently stopped providing a great deal of detail in their vulnerability advisories, so it’s not entirely clear how this is being exploited.
But Kevin Breen , director of
Talos
Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-01-12·CVSS 7.8
[HIGH] Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Asheer Malhotra.
Microsoft released its monthly security update Tuesday, disclosing 83 vulnerabilities across its suite of products to kick-off 2021.
There are only 10 critical vulnerabilities as part of this release, while there are two moderate-severity exploits, and the remainder is considered “important.” Users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation of all these bugs.
The security updates cover several different products and services, including the Microsoft Defender antivirus software, the Microsoft Remote Procedure Call tools and Bluetooth communication with Windows devices
Krebs
Microsoft Patch Tuesday, January 2021 Edition
blogs_krebs·2021-01-12·CVSS 8.3
[HIGH] Microsoft Patch Tuesday, January 2021 Edition
Microsoft today released updates to plug more than 80 security holes in its Windows operating systems and other software, including one that is actively being exploited and another which was disclosed prior to today. Ten of the flaws earned Microsoft’s most-dire “critical” rating, meaning they could be exploited by malware or miscreants to seize remote control over unpatched systems with little or no interaction from Windows users.
Most concerning of this month’s batch is probably a critical bug (CVE-2021-1647) in Microsoft’s default anti-malware suite — Windows Defender — that is seeing active exploitation. Microsoft recently stopped providing a great deal of detail in their vulnerability advisories, so it’s not entirely clear how this is being exploited.
But Kevin Breen, director of re
Qualys
January 2021 Patch Tuesday – 83 Vulnerabilities, 10 Critical, One Zero Day, Adobe | Qualys
blogs_qualys·2021-01-12·CVSS 7.8
[HIGH] January 2021 Patch Tuesday – 83 Vulnerabilities, 10 Critical, One Zero Day, Adobe | Qualys
This month’s Microsoft Patch Tuesday addresses 83 vulnerabilities. The 10 Critical vulnerabilities cover Windows codecs, Office, HEVC video extensions, RPC runtime, and several other workstation vulnerabilities. Adobe released patches today for Photoshop, Campaign Classic, InCopy, Illustrator, Captivate, Bridge and Animate.
### Workstation Patches
Office and Edge vulnerabilities should be prioritized for workstation-type devices, meaning any system that is used to access email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
### Microsoft Defender RCE Zero Day
Microsoft patches Defender Remote Code Execution vulnerability (CVE-2021-1647) in today’s patch release for Microsoft Malware Protection Engine. Microsoft state
Qualys
January 2021 Patch Tuesday – 83 Vulnerabilities, 10 Critical, One Zero Day, Adobe
blogs_qualys·2021-01-12·CVSS 7.8
[HIGH] January 2021 Patch Tuesday – 83 Vulnerabilities, 10 Critical, One Zero Day, Adobe
This month’s Microsoft Patch Tuesday addresses 83 vulnerabilities. The 10 Critical vulnerabilities cover Windows codecs, Office, HEVC video extensions, RPC runtime, and several other workstation vulnerabilities. Adobe released patches today for Photoshop, Campaign Classic, InCopy, Illustrator, Captivate, Bridge and Animate.
## Workstation Patches
Office and Edge vulnerabilities should be prioritized for workstation-type devices, meaning any system that is used to access email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
## Microsoft Defender RCE Zero Day
Microsoft patches Defender Remote Code Execution vulnerability ( CVE-2021-1647 ) in today’s patch release for Microsoft Malware Protection Engine. Microsoft state
Tenable
Microsoft’s January 2021 Patch Tuesday Addresses 83 CVEs
blogs_tenable·2021-01-12
Microsoft’s January 2021 Patch Tuesday Addresses 83 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-01-12·CVSS 7.8
[HIGH] Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Asheer Malhotra.
Microsoft released its monthly security update Tuesday, disclosing 83 vulnerabilities across its suite of products to kick-off 2021.
There are only 10 critical vulnerabilities as part of this release, while there are two moderate-severity exploits, and the remainder is considered “important.” Users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation of all these bugs.
The security updates cover several different products and services, including the Microsoft Defender antivirus software, the Microsoft Remote Procedure Call tools and Bluetooth communication with Windows devices. Talos also released a new set of SNORTⓇ rules that provide coverage for some of thes
2021-01-12
Published