CVE-2021-42321 & CVE-2021-42292
ID: 57c4427e-6096-53a4-88f1-69f455816177
STIX ID: report--57c4427e-6096-53a4-88f1-69f455816177
Feed Name: Arctic Wolf Blog
On November 9, 2021 Microsoft released security updates addressing two actively exploited vulnerabilities: CVE-2021-42292 (Microsoft Excel security feature bypass that can allow local code execution via a crafted file) and CVE-2021-42321 (post-authentication remote code execution in on-premises Microsoft Exchange Server 2016 and 2019). Microsoft reports limited exploitation, has provided detection guidance (including a PowerShell query for Exchange), and Arctic Wolf recommends reviewing affected versions and applying patches as soon as possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
