Consultores de seguridad de Zscaler
Zscaler protects against 7 new vulnerabilities for Windows DirectX, Internet Explorer, Microsoft Exchange Server, Microsoft Graphics Component and Windows DNS Server.
Zscaler, working with Microsoft through their MAPP program, has proactively deployed protection for the following 7 vulnerabilities included in the March 2021 Microsoft security bulletins. Zscaler will continue to monitor exploits associated with all vulnerabilities in the March release and deploy additional protections, as necessary. Zscaler has published an advisory last week regarding the coverage for exploits related to Microsoft Exchange Servers. Zscaler has also published a blog on how to Disrupt the Microsoft Exchange Attacks with Zero Trust Architecture.
CVE-2021-24095 – DirectX Elevation of Privilege Vulnerability
Severity: Important
Affected Software
- Windows 10 Version 1803 for 32-bit Systems
- Windows 10 Version 1803 for x64-based Systems
- Windows 10 Version 1803 for ARM64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows 10 Version 1909 for 32-bit Systems
- Windows 10 Version 1909 for x64-based Systems
- Windows 10 Version 1909 for ARM64-based Systems
- Windows Server, version 1909 (Server Core installation)
- Windows 10 Version 2004 for 32-bit Systems
- Windows 10 Version 2004 for ARM64-based Systems
- Windows 10 Version 2004 for x64-based Systems
- Windows Server, version 2004 (Server Core installation)
- Windows 10 Version 20H2 for x64-based Systems
- Windows 10 Version 20H2 for 32-bit Systems
- Windows 10 Version 20H2 for ARM64-based Systems
- Windows Server, version 20H2 (Server Core Installation)
CVE-2021-26411 – Internet Explorer Memory Corruption Vulnerability
Severity: Critical
Affected Software
- Internet Explorer 9 on Windows Server 2008 for 32-bit Systems Service Pack 2
- Internet Explorer 9 on Windows Server 2008 for x64-based Systems Service Pack 2
- Internet Explorer 11 on Windows 10 Version 1803 for 32-bit Systems
- Internet Explorer 11 on Windows 10 Version 1803 for x64-based Systems
- Internet Explorer 11 on Windows 10 Version 1803 for ARM64-based Systems
- Internet Explorer 11 on Windows 10 Version 1809 for 32-bit Systems
- Internet Explorer 11 on Windows 10 Version 1809 for x64-based Systems
- Internet Explorer 11 on Windows 10 Version 1809 for ARM64-based Systems
- Internet Explorer 11 on Windows Server 2019
- Internet Explorer 11 on Windows 10 Version 1909 for 32-bit Systems
- Internet Explorer 11 on Windows 10 Version 1909 for x64-based Systems
- Internet Explorer 11 on Windows 10 Version 1909 for ARM64-based Systems
- Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems
- Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems
- Internet Explorer 11 on Windows 10 Version 2004 for 32-bit Systems
- Internet Explorer 11 on Windows 10 Version 2004 for ARM64-based Systems
- Internet Explorer 11 on Windows 10 Version 2004 for x64-based Systems
- Internet Explorer 11 on Windows 10 Version 20H2 for x64-based Systems
- Internet Explorer 11 on Windows 10 Version 20H2 for 32-bit Systems
- Internet Explorer 11 on Windows 10 Version 20H2 for ARM64-based Systems
- Internet Explorer 11 on Windows 10 for 32-bit Systems
- Internet Explorer 11 on Windows 10 for x64-based Systems
- Internet Explorer 11 on Windows 10 Version 1607 for 32-bit Systems
- Internet Explorer 11 on Windows 10 Version 1607 for x64-based Systems
- Internet Explorer 11 on Windows 7 for 32-bit Systems Service Pack 1
- Internet Explorer 11 on Windows 7 for x64-based Systems Service Pack 1
- Internet Explorer 11 on Windows 8.1 for 32-bit systems
- Internet Explorer 11 on Windows 8.1 for x64-based systems
- Internet Explorer 11 on Windows RT 8.1
- Internet Explorer 11 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Internet Explorer 11 on Windows Server 2012
- Internet Explorer 11 on Windows Server 2012 R2
- Internet Explorer 11 on Windows Server 2016
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for 32-bit Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for x64-based Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for ARM64-based Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1809 for 32-bit Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1809 for x64-based Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1809 for ARM64-based Systems.
- Microsoft Edge (EdgeHTML-based) on Windows Server 2019
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1909 for 32-bit Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1909 for x64-based Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1909 for ARM64-based Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1903 for x64-based Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1903 for ARM64-based Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 2004 for 32-bit Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 2004 for ARM64-based Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 2004 for x64-based Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 20H2 for x64-based Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 20H2 for 32-bit Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 20H2 for ARM64-based Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 for 32-bit Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 for x64-based Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1607 for 32-bit Systems.
- Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1607 for x64-based Systems.
- Microsoft Edge (EdgeHTML-based) on Windows Server 2016
CVE-2021-26855 – Microsoft Exchange Server Remote Code Execution Vulnerability
Severity: Critical
Affected Software
- Microsoft Exchange Server 2016 Cumulative Update 19
- Microsoft Exchange Server 2019 Cumulative Update 8
- Microsoft Exchange Server 2013 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 7
- Microsoft Exchange Server 2016 Cumulative Update 18
CVE-2021-26863 – Windows Win32k Elevation of Privilege Vulnerability
Severity: Important
Affected Software
- Windows 10 Version 1803 for 32-bit Systems
- Windows 10 Version 1803 for x64-based Systems
- Windows 10 Version 1803 for ARM64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows 10 Version 1909 for 32-bit Systems
- Windows 10 Version 1909 for x64-based Systems
- Windows 10 Version 1909 for ARM64-based Systems
- Windows Server, version 1909 (Server Core installation)
- Windows 10 Version 2004 for 32-bit Systems
- Windows 10 Version 2004 for ARM64-based Systems
- Windows 10 Version 2004 for x64-based Systems
- Windows Server, version 2004 (Server Core installation)
- Windows 10 Version 20H2 for x64-based Systems
- Windows 10 Version 20H2 for 32-bit Systems
- Windows 10 Version 20H2 for ARM64-based Systems
- Windows Server, version 20H2 (Server Core Installation)
CVE-2021-26868 – Windows Graphics Component Elevation of Privilege Vulnerability
Severity: Important
Affected Software
- Windows 10 Version 1803 for 32-bit Systems
- Windows 10 Version 1803 for x64-based Systems
- Windows 10 Version 1803 for ARM64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows 10 Version 1909 for 32-bit Systems
- Windows 10 Version 1909 for x64-based Systems
- Windows 10 Version 1909 for ARM64-based Systems
- Windows Server, version 1909 (Server Core installation)
- Windows 10 Version 2004 for 32-bit Systems
- Windows 10 Version 2004 for ARM64-based Systems
- Windows 10 Version 2004 for x64-based Systems
- Windows Server, version 2004 (Server Core installation)
- Windows 10 Version 20H2 for x64-based Systems
- Windows 10 Version 20H2 for 32-bit Systems
- Windows 10 Version 20H2 for ARM64-based Systems
- Windows Server, version 20H2 (Server Core Installation)
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows 8.1 for 32-bit systems
- Windows 8.1 for x64-based systems
- Windows RT 8.1
- Windows Server 2012
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)
CVE-2021-26877 – Windows DNS Server Remote Code Execution Vulnerability
Severity: Important
Affected Software
- Windows 10 Version 20H2 for x64-based Systems
- Windows 10 Version 20H2 for 32-bit Systems
- Windows 10 Version 20H2 for ARM64-based Systems
- Windows Server, version 20H2 (Server Core Installation)
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows 10 Version 1909 for 32-bit Systems
- Windows 10 Version 1909 for x64-based Systems
- Windows 10 Version 1909 for ARM64-based Systems
- Windows Server, version 1909 (Server Core installation)
- Windows 10 Version 2004 for 32-bit Systems
- Windows 10 Version 2004 for ARM64-based Systems
- Windows 10 Version 2004 for x64-based Systems
- Windows Server, version 2004 (Server Core installation)
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows 7 for 32-bit Systems Service Pack 1
- Windows 7 for x64-based Systems Service Pack 1
- Windows 8.1 for 32-bit systems
- Windows 8.1 for x64-based systems
- Windows RT 8.1
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2012
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)
CVE-2021-26897 – Windows DNS Server Remote Code Execution Vulnerability
Severity: Critical
Affected Software
- Windows 10 Version 20H2 for x64-based Systems
- Windows 10 Version 20H2 for 32-bit Systems
- Windows 10 Version 20H2 for ARM64-based Systems
- Windows Server, version 20H2 (Server Core Installation)
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows 10 Version 1909 for 32-bit Systems
- Windows 10 Version 1909 for x64-based Systems
- Windows 10 Version 1909 for ARM64-based Systems
- Windows Server, version 1909 (Server Core installation)
- Windows 10 Version 2004 for 32-bit Systems
- Windows 10 Version 2004 for ARM64-based Systems
- Windows 10 Version 2004 for x64-based Systems
- Windows Server, version 2004 (Server Core installation)
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows 7 for 32-bit Systems Service Pack 1
- Windows 7 for x64-based Systems Service Pack 1
- Windows 8.1 for 32-bit systems
- Windows 8.1 for x64-based systems
- Windows RT 8.1
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2012
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)