CVE-2021-31978
published 2021-06-08CVE-2021-31978: Microsoft Defender Denial of Service Vulnerability
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
1.23%
65.7th percentile
Microsoft Defender Denial of Service Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | malware_protection_engine | < 1.1.18200.3 | 1.1.18200.3 |
| microsoft | microsoft_malware_protection_engine | >= 1.1.0.0 < Version 1.1.18200.3 | Version 1.1.18200.3 |
| msrc | microsoft_malware_protection_engine | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9mqr-qv46-7v82: Microsoft Defender Denial of Service Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-31978 [MEDIUM] GHSA-9mqr-qv46-7v82: Microsoft Defender Denial of Service Vulnerability
Microsoft Defender Denial of Service Vulnerability
Microsoft
Microsoft Defender Denial of Service Vulnerability
vendor_msrc·2021-06-08·CVSS 5.5
CVE-2021-31978 [MEDIUM] Microsoft Defender Denial of Service Vulnerability
Microsoft Defender Denial of Service Vulnerability
FAQ:
References
Identification
First version of the Microsoft Malware Protection Engine with this vulnerability addressed
Version 1.1.18200.3
See Manage Updates Baselines Microsoft Defender Antivirus for more information.
Microsoft Defender is disabled in my environment, why are vulnerability scanners showing that I am vulnerable to this issue?
Vulnerability scanners are looking for specific binaries and version numbers on devices. Microsoft Defender files are still on disk even when disabled. Systems that have disabled Microsoft Defender are not in an exploitable state.
Why is no action required to install this update?
In response to a constantly changing threat landscape, Microsoft frequently updates malware definitions and the Mi
No detection rules found.
No public exploits indexed.
Trendmicro
June Patch Tuesday: Internet Explorer Finally Laid to Rest
blogs_trendmicro·2021-06-08·CVSS 5.5
[MEDIUM] June Patch Tuesday: Internet Explorer Finally Laid to Rest
Ausnutzung von Schwachstellen
## June Patch Tuesday: Internet Explorer Finally Laid to Rest
The June 2021 Patch Tuesday cycle offers good news to both IT and website administrators.
By: Trend Micro Jun 08, 2021 Read time: ( words)
Save to Folio
The June 2021 Patch Tuesday cycle offers good news to both IT and website administrators. For the former, the number of bulletins issued this month is, at 50, far lower than we’ve become accustomed to in recent months. The latter group, however, has much better news to process this month: Internet Explorer support finally comes to an end.
June Patches: Fifty Bulletins, But Only Five Critical
Of this month’s 50 bulletins, only five were rated by Microsoft as Critical. One of these bulletins covers a vulnerability in Microsoft Defender ( CVE-20
Trendmicro
June Patch Tuesday: Internet Explorer Finally Laid to Rest
blogs_trendmicro·2021-06-08·CVSS 5.5
[MEDIUM] June Patch Tuesday: Internet Explorer Finally Laid to Rest
Exploits & Vulnerabilities
## June Patch Tuesday: Internet Explorer Finally Laid to Rest
The June 2021 Patch Tuesday cycle offers good news to both IT and website administrators.
By: Trend Micro 2021/06/08 Read time: ( words)
Save to Folio
The June 2021 Patch Tuesday cycle offers good news to both IT and website administrators. For the former, the number of bulletins issued this month is, at 50, far lower than we’ve become accustomed to in recent months. The latter group, however, has much better news to process this month: Internet Explorer support finally comes to an end.
June Patches: Fifty Bulletins, But Only Five Critical
Of this month’s 50 bulletins, only five were rated by Microsoft as Critical. One of these bulletins covers a vulnerability in Microsoft Defender ( CVE-2021-31
Trendmicro
June Patch Tuesday: Internet Explorer Finally Laid to Rest
blogs_trendmicro·2021-06-08·CVSS 5.5
[MEDIUM] June Patch Tuesday: Internet Explorer Finally Laid to Rest
Sfruttamento vulnerabilità
## June Patch Tuesday: Internet Explorer Finally Laid to Rest
The June 2021 Patch Tuesday cycle offers good news to both IT and website administrators.
By: Trend Micro Jun 08, 2021 Read time: ( words)
Save to Folio
The June 2021 Patch Tuesday cycle offers good news to both IT and website administrators. For the former, the number of bulletins issued this month is, at 50, far lower than we’ve become accustomed to in recent months. The latter group, however, has much better news to process this month: Internet Explorer support finally comes to an end.
June Patches: Fifty Bulletins, But Only Five Critical
Of this month’s 50 bulletins, only five were rated by Microsoft as Critical. One of these bulletins covers a vulnerability in Microsoft Defender ( CVE-2021-
Trendmicro
June Patch Tuesday: Internet Explorer Finally Laid to Rest
blogs_trendmicro·2021-06-08·CVSS 5.5
[MEDIUM] June Patch Tuesday: Internet Explorer Finally Laid to Rest
Exploits y vulnerabilidades
## June Patch Tuesday: Internet Explorer Finally Laid to Rest
The June 2021 Patch Tuesday cycle offers good news to both IT and website administrators.
By: Trend Micro Jun 08, 2021 Read time: ( words)
Save to Folio
The June 2021 Patch Tuesday cycle offers good news to both IT and website administrators. For the former, the number of bulletins issued this month is, at 50, far lower than we’ve become accustomed to in recent months. The latter group, however, has much better news to process this month: Internet Explorer support finally comes to an end.
June Patches: Fifty Bulletins, But Only Five Critical
Of this month’s 50 bulletins, only five were rated by Microsoft as Critical. One of these bulletins covers a vulnerability in Microsoft Defender ( CVE-2021
Trendmicro
June Patch Tuesday: Internet Explorer Finally Laid to Rest
blogs_trendmicro·2021-06-08·CVSS 5.5
[MEDIUM] June Patch Tuesday: Internet Explorer Finally Laid to Rest
Exploits & Vulnerabilities
# June Patch Tuesday: Internet Explorer Finally Laid to Rest
The June 2021 Patch Tuesday cycle offers good news to both IT and website administrators.
By: Trend Micro
2021/06/08
Read time: ( words)
Save to Folio
The June 2021 Patch Tuesday cycle offers good news to both IT and website administrators. For the former, the number of bulletins issued this month is, at 50, far lower than we’ve become accustomed to in recent months. The latter group, however, has much better news to process this month: Internet Explorer support finally comes to an end.
June Patches: Fifty Bulletins, But Only Five Critical
Of this month’s 50 bulletins, only five were rated by Microsoft as Critical. One of these bulletins covers a vulnerability in Microsoft Defender (CVE-2021-319
Trendmicro
June Patch Tuesday: Internet Explorer Finally Laid to Rest
blogs_trendmicro·2021-06-08·CVSS 5.5
[MEDIUM] June Patch Tuesday: Internet Explorer Finally Laid to Rest
Exploits & Vulnerabilities
## June Patch Tuesday: Internet Explorer Finally Laid to Rest
The June 2021 Patch Tuesday cycle offers good news to both IT and website administrators.
By: Trend Micro Jun 08, 2021 Read time: ( words)
Save to Folio
The June 2021 Patch Tuesday cycle offers good news to both IT and website administrators. For the former, the number of bulletins issued this month is, at 50, far lower than we’ve become accustomed to in recent months. The latter group, however, has much better news to process this month: Internet Explorer support finally comes to an end.
June Patches: Fifty Bulletins, But Only Five Critical
Of this month’s 50 bulletins, only five were rated by Microsoft as Critical. One of these bulletins covers a vulnerability in Microsoft Defender ( CVE-2021-
Qualys
Microsoft & Adobe Patch Tuesday (June 2021) – Microsoft 50 Vulnerabilities with 5 Critical, Adobe 21 Critical Vulnerabilities
blogs_qualys·2021-06-08·CVSS 5.2
CVE-2021-31985 [MEDIUM] Microsoft & Adobe Patch Tuesday (June 2021) – Microsoft 50 Vulnerabilities with 5 Critical, Adobe 21 Critical Vulnerabilities
## Microsoft Patch Tuesday – June 2021
Microsoft patched 50 CVEs in their June 2021 Patch Tuesday release, and five of them are rated as critical severity. Six have applicable exploits.
## Critical Microsoft Vulnerabilities Patched
CVE-2021-31985 – Microsoft Defender Remote Code Execution Vulnerability
Microsoft released patches addressing a critical RCE vulnerability in its Defender product (CVE-2021-31985). This CVE has a high likelihood of exploitability and is assigned a CVSSv3 base score of 7.8 by the vendor.
CVE-2021-31959 – Scripting Engine Memory Corruption Vulnerability
Microsoft released patches addressing a critical memory corruption vulnerability in the Chakra JScript scripting engine. This vulnerability impacts Windows RT, Windows 7, Windows 8, Windows 10, Windows Server
Trendmicro
June Patch Tuesday: Internet Explorer Finally Laid to Rest
blogs_trendmicro·2021-06-08·CVSS 5.5
[MEDIUM] June Patch Tuesday: Internet Explorer Finally Laid to Rest
Exploits & Vulnerabilities
## June Patch Tuesday: Internet Explorer Finally Laid to Rest
The June 2021 Patch Tuesday cycle offers good news to both IT and website administrators.
By: Trend Micro Jun 08, 2021 Read time: ( words)
Save to Folio
The June 2021 Patch Tuesday cycle offers good news to both IT and website administrators. For the former, the number of bulletins issued this month is, at 50, far lower than we’ve become accustomed to in recent months. The latter group, however, has much better news to process this month: Internet Explorer support finally comes to an end.
June Patches: Fifty Bulletins, But Only Five Critical
Of this month’s 50 bulletins, only five were rated by Microsoft as Critical. One of these bulletins covers a vulnerability in Microsoft Defender ( CVE-2021-
2021-06-08
Published