Skip to main content
SolarWinds MSP
  • Login
  • Support
  • Partnerships
    • Partnerships Overview
    • Solution Provider Program
    • Technology Alliance Program
    • Distributor Program
SolarWinds MSP
  • Products
    • SolarWinds N-central Automate what you need. Tackle complex networks. Try this remote monitoring and management solution built to help maximize efficiency and scale.
    • SolarWinds RMM Start fast. Grow at your own pace. Try this powerful but simple remote monitoring and management solution.
    • SolarWinds EDR Defend against ransomware, zero-day attacks, and evolving online threats with Endpoint Detection and Response
    • SolarWinds Backup Manage data protection for servers, workstations applications, documents and Microsoft 365 from one SaaS dashboard.
    • Mail Protection & Archiving Protect users from email threats and downtime.
    • Password Management Easily adopt and demonstrate best practice password and documentation management workflows.
      • Passportal Demo
    • PSA & Ticketing Manage ticketing, reporting, and billing to increase helpdesk efficiency.
    • Remote Support Help support customers and their devices with remote support tools designed to be fast and powerful.
  • Solutions

    I'm looking for...

    • Security Solutions
    • Monitoring Solutions
    • Efficiency Solutions
  • Resources
    • Blog
    • Webcasts & Events
    • Ask the N-central Experts
    • Daily Live Demos
    • RMM Foundations Training
    • Upcoming Events
    • Upcoming Webcasts
    • Resource Center
    • COVID-19 Resources
    • Resource Library
      • Case Studies
      • Product Information
      • eBooks
      • White Papers
      • Infographics
    • SolarWinds MSP Free Tools
    • GDPR Resource Center
    • Security Resource Center
    • MSP Institute Webinar Series
    • MSP Advice Project
  • About
    • Contact
    • Customer Success
    • Worldwide sales and support
    • Careers
    • Awards and Recognition
    • Get A Quote
    • Newsroom
      • Press Releases
      • In The News
      • Media Contacts
      • COVID-19 Response
    • Leadership Team
    • Legal
      • Cookie Policy
      • Privacy Notice
      • Software Services Agreement
      • Terms of Use
      • Backup Fair Use Policy
    • Security
      • SolarWinds Security Statement
      • Vendor Data Protection Requirements
    • Support
  • IT Departments
  • Contact Sales
    • Get A Quote
    • General Inquiry
  • TRY NOW
    • SolarWinds RMM
    • SolarWinds Backup
    • MSP Manager
    • SolarWinds Passportal
    • SolarWinds N-central
    • SolarWinds Mail Assure
    • SolarWinds Risk Intelligence
    • SolarWinds Take Control
  • Request a Quote
  • Try Now
    • SolarWinds RMM
    • SolarWinds N-central
    • SolarWinds Backup
    • MSP Manager
    • SolarWinds Mail Assure
    • SolarWinds Passportal
    • SolarWinds Risk Intelligence
    • SolarWinds Take Control
Request quote
Filter Blogs
  • Filter by:
  • MSP Business
    • Automation
    • Backup & Disaster Recovery
    • Security-series
    • Best Practices
    • Business
    • Business Growth
    • Business Risk
    • Cloud Computing
    • Customer Service
    • Cybersecurity
    • Cybersecurity Awareness Month
    • Data
    • GDPR
    • Internet of Things
    • IT Support
    • ITSM
    • LOGICcards
    • Machine Learning
    • Mail
    • Managed Services
    • Marketing
    • Mobile
    • Networking
    • Operations
    • Podcast
    • Product
    • PSA
    • Remote Management
    • Research & Trends
    • Risk Intelligence
    • Security
    • Security Vlog
    • Service Desk
    • Services & Support
    • The Head Nerds
    • Tips & Advice
    • Training
Home Blog MSP Business Security January 2021 Patch Tuesday: One Actively Exploited Vulnerability and a Few Likely to Be
Security

January 2021 Patch Tuesday: One Actively Exploited Vulnerability and a Few Likely to Be

By Gill Langston
14 January, 2021

Here we are in a new year and Microsoft has released their first set of patches. This month we continue the recent trend of less than 100 vulnerabilities fixed by Microsoft. While there are some critical vulnerabilities (and one that will get fixed without you having to deploy a patch), I was still struck by how few critical fixes were included this month. 

All in all, we saw 83 vulnerabilities fixed, with 10 marked critical and 71 marked important. Interestingly, the important fixes are the ones marked with a higher likelihood of being exploited. So let’s review those critical ones along with the others that warrant attention.

Operating system 

Most of the operating system vulnerabilities this month all have the same description and details. There are five vulnerabilities titled Remote Procedure Call Runtime Remote Code Execution Vulnerability. CVE-2021-1658, CVE-2021-1660, CVE-2021-1667, CVE-2021-1673, and CVE-2021-1666 are all RPC vulnerabilities which can be executed across the network without user interaction required. These vulnerabilities all have a CVSS score of 8.8, the highest in this month’s batch. This vulnerability affects Windows 7 through the current version of Windows 10, including the corresponding server and core versions.

Next is a GDI+ Remote Code Execution Vulnerability, CVE-2021-1665. This vulnerability requires user interaction by clicking on an attachment and would give the attacker full access to the target system. It has a CVSS of 7.8 and is listed by Microsoft as exploitation less likely.

CVE-2021-1643 is a HEVC Video Extensions Remote Code Execution Vulnerability in the Microsoft Store Apps that uses the video extension. It’s listed as exploitation less likely. These apps generally update themselves unless you have blocked updates in the Windows Store. The vulnerability in the link includes a PowerShell script you can use to determine if you need to update any affected apps by checking the version of the extension’s package.

The final “Critical” on the operating system side is CVE-2021-1668, titled Microsoft DTV-DVD Video Decoder Remote Code Execution Vulnerability. This vulnerability requires user interaction (such as opening a malicious file) on the system and would give the attacker the ability to execute code. It’s also listed as exploitation less likely.

Browsers

There is only one critical vulnerability in the browsers this month. CVE-2021-1705 is a Microsoft Edge (HTML-based) Memory Corruption Vulnerability which would grant an attacker full access to a system if a user visited a malicious site from a spam or phishing email. It’s also listed as exploitation less likely. This vulnerability affects all systems that support the Edge-HTML version of Microsoft Edge. As you’re aware, the newest versions of Edge are based on Chromium and self-update. It might be time to consider moving to that flavor if you have not already.

Other applications

CVE-2021-1647 is a Microsoft Defender Remote Code Execution Vulnerability that Microsoft states is currently under active attack. Listed as exploitation detected, this vulnerability requires access to the system. Vulnerabilities like this are used many times in multi-stage attacks, using one vector to gain access to the system, and then a vulnerability like this to execute additional code for the next stage in their attack. Luckily, Microsoft updates their engine along with their definitions in regular updates. Simply ensure any systems running Windows Defender are configured for regular updates and it will resolve itself. In this case, make sure Defender is running Microsoft Malware Protection Engine version 1.1.17700.4 or later.

Important vulnerabilities worth some attention

We often run across vulnerabilities that are only listed as important but Microsoft marks them as exploitation more likely. This month we have two of those.

CVE-2021-1707 is a Microsoft SharePoint Server Remote Code Execution Vulnerability that would allow code to be executed on the kernel of the system hosting SharePoint if an application package were uploaded to the server. This is a higher-complexity attack as the attacker needs to have access to a user account with permissions to upload to SharePoint. It also has a CVSS score of 8.8, which is on the higher end of the scale. This vulnerability affects SharePoint Foundation 2010 and 2013, SharePoint Enterprise Server 2016, and SharePoint Server 2019.

Finally, we have a Windows Win32k Elevation of Privilege Vulnerability, CVE-2021-1709. It’s a locally exploited vulnerability that requires no user interaction. An attacker could use this vulnerability to gain higher privileges during an attack with the intention of moving to other systems during a multi-stage attack. It has a CVSS of 7.0, and affects Windows 7 up to the current version of Windows 10, including Server and Core versions.

Microsoft also issued fixes for Office, SQL, Windows Installer, ASP.Net, Hyper-V, and Windows DNS. From a priority standpoint, if you’re running Windows Defender, make sure it’s receiving updates as expected. Next, focus on workstations, your SharePoint servers, and then move to your SQL and Office updates. Also make sure you take the time to update any DNS servers in your environment, as they can sometimes get skipped in favor of maintaining uptime.

 

Gill Langston is head security nerd for SolarWinds MSP. You can follow Gill on Twitter at @cybersec_nerd

 

You might also like...
Security

December 2020 Patch Tuesday—A quiet(er) finish to a busy year in vulnerabilities

Security

National Computer Security Day—It’s Not Just About the Computer Anymore

Security

November 2020 Patch Tuesday Update: 111 CVE Numbers Addressed

Security

US-CERT Releases Warning to Healthcare Organizations about Elevated Ransomware Risks

Security

EDR Is Now Integrated with SolarWinds RMM

Security

October 2020 Patch Tuesday—Smaller than usual, but some systems need patching now

Want to stay up to date?

Get the latest MSP tips, tricks, and ideas sent to your inbox each week.

Loading form....

If the form does not load in a few seconds, it is probably because your browser is using Tracking Protection. This is either an Ad Blocker plug-in or your browser is in private mode. Please allow tracking on this page to request a subscription.

Note: Firefox users may see a shield icon to the left of the URL in the address bar. Click on this to disable tracking protection for this session/site

Recent Posts
  • January 2021 Patch Tuesday: One Actively Exploited Vulnerability and a Few Likely to Be
  • TAP Blog Series: Maximizing Your Service Delivery Opportunity
  • Why Do MSPs Choose SolarWinds Backup? IT Central Station Finds Out
  • Seven Features Remote Assistance Software Should Have
  • TAP Blog Series: Creating Your Automation Strategy—Three Key Components You Must Have in Place
Categories:
  • Security (229)
  • Tips & Advice (122)
  • Best Practices (94)
  • Managed Services (86)
  • Backup & Disaster Recovery (82)
  • Business Growth (75)
  • The Head Nerds (74)
  • IT Support (41)
  • Business (39)
  • Cybersecurity (37)
  • Automation (36)
  • Operations (33)
  • Mail (33)
  • Remote Management (27)
  • ITSM (25)
  • Cloud Computing (21)
  • Networking (21)
  • Data (21)
  • Marketing (14)
  • Product (11)
  • PSA (10)
  • Mobile (4)
  • Risk Intelligence (4)
  • Service Desk (4)
  • Services & Support (4)
  • Internet of Things (3)
  • Customer Service (3)
  • Research & Trends (2)
  • Training (2)
  • GDPR (2)
  • Business Risk (1)
  • LOGICcards (1)
Show moreless
SolarWinds MSP

Products
  • SolarWinds RMM
  • SolarWinds N-central
  • SolarWinds Backup
  • SolarWinds EDR
  • SolarWinds MSP Manager
  • SolarWinds Mail Assure
  • SolarWinds Risk Intelligence
  • SolarWinds Take Control
  • SolarWinds Passportal
  • All Products Use Cases
Solutions
  • Security Solutions
  • Monitoring Solutions
  • Efficiency Solutions
  • Identify which RMM solution is right for me
  • Drive Efficiency with Automation
  • Manage my MSP Business More Efficiently
  • Manage my IT Department More Efficiently
  • Layered Security
  • Cross-Platform Support
  • Data-Driven Insights
About
  • About Us
  • Careers
  • Newsroom
  • Leadership Team
  • Upcoming Events
  • Subscription Preferences
  • SolarWinds
  • SolarWinds Trust Center
  • COVID-19 Response
Support
  • SolarWinds RMM
  • Solarwinds N-central
  • SolarWinds Backup
  • SolarWinds Mail Assure
  • SolarWinds Take Control
  • SolarWinds MSP Manager
  • Solarwinds Risk Intelligence
  • Solarwinds Threat Monitor
  • SolarWinds Passportal
  • SolarWinds Take Control Downloads
  • Backup & Recovery Downloads
  • Service Status

Footer 2

  • Legal Documents
  • Privacy
  • California Privacy Rights
  • Security Information
  • Sitemap

© SolarWinds MSP Canada ULC and SolarWinds MSP UK Ltd.
All Rights Reserved.