Team OS : Your Only Destination To Custom OS !!

Welcome to TeamOS Community, Register or Login to the Community to Download Torrents, Get Access to Shoutbox, Post Replies, Use Search Engine and many more features. Register Today!

Tech News Microsoft Windows 10—Update Now Warning For Millions As Attackers Strike

Most information security professionals are scrambling to deal with the ongoing and truly scary Log4J (also known as Log4Shell) vulnerability. But, sadly, Log4J is not the only shark in the security swimming pool: millions of Windows 10 users need to be aware of one zero-day threat in particular.

The bad news is that attackers are already exploiting CVE-2021-43890 to install the very nasty Emotet, or Trickbot, credential-stealing malware. The good news is that Microsoft has the fix, and you need to apply it. Now.

Yes, this week sees Microsoft's final Medicines Tuesday round of security fixes in 2021, and it's a big one. In all, more than sixty vulnerabilities have been addressed across the Microsoft product range, including Windows, Visual Studio, Office, PowerShell and SharePoint Server, to name but a few. Seven of the patched vulnerabilities have been given a critical rating, and there are six zero-days fixed for good measure.

However, of concern to millions of Windows 10 users is that zero-day, publicly disclosed, and exploited by attackers in the wild. CVE-2021-43890 is a spoofing vulnerability in the Windows AppX installer and is being used to deliver some genuinely gruesome malware.

Exploits take the form of malicious software packages installed when unsuspecting users open infected documents and the like. Obviously, those users with admin account rights will be most at risk here. That said, when chained with another exploit it could be possible to impact those with fewer user rights to gain enough privilege to execute the malware code.

Microsoft has confirmed that exploitation is already ongoing: "Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader," it stated in the latest security update guide.

"Given the critical nature of this vulnerability and the fact that there is active exploitation," Chad McNaughton, technical community manager at Automox, said, "organizations should take immediate action to remediate within the next 24 hours."

That warning was given, dear reader, on 14 December. The clock is, therefore, well and truly ticking on this one.

The remaining zero-day vulnerabilities that have been addressed by Microsoft this Medicines Tuesday are:

CVE-2021-43240 is an elevation of privilege vulnerability affecting Windows 10, Windows 11 and Windows Server users.
CVE-2021-41333 is an elevation of privilege vulnerability affecting Windows 10, Windows 11 and Windows Server users.
CVE-2021-43880 is an elevation of privilege vulnerability affecting Windows 11 users.
CVE-2021-43883 is an elevation of privilege vulnerability affecting Windows 10, Windows 11 and Windows Server users.
CVE-2021-43893 is an elevation of privilege vulnerability affecting Windows 10, Windows 11 and Windows Server users.
 

pascalwil

✅ Verified Member
Member
Downloaded
1.3 TB
Uploaded
36.2 TB
Ratio
28.55
Seedbonus
23,798
Upload Count
0 (0)
Member for 8 years
Thanks a lot. Any link to MS to download fix?
 

TheHarperdragon

Power User
✅ Verified Member
Member
Downloaded
918.1 GB
Uploaded
157.5 TB
Ratio
175.7
Seedbonus
738,680
Upload Count
0 (0)
Member for 10 years
Nothing yet but knowing Microcrap .. probably soon
 

pascalwil

✅ Verified Member
Member
Downloaded
1.3 TB
Uploaded
36.2 TB
Ratio
28.55
Seedbonus
23,798
Upload Count
0 (0)
Member for 8 years
Thanks for the reply. You wrote "The good news is that Microsoft has the fix, and you need to apply it. Now."
And "Yes, this week sees Microsoft's final Medicines Tuesday round of security fixes in 2021, and it's a big one"

Anyone has a link to this Medicines Tuesday? Looking for it on the web I get lost. Thanks
 

Chuck

🤴 Super Admin
Downloaded
300.6 GB
Uploaded
2.9 TB
Ratio
9.91
Seedbonus
591,311
Upload Count
24 (26)
Member for 5 years
Thanks for the reply. You wrote "The good news is that Microsoft has the fix, and you need to apply it. Now."
And "Yes, this week sees Microsoft's final Medicines Tuesday round of security fixes in 2021, and it's a big one"

Anyone has a link to this Medicines Tuesday? Looking for it on the web I get lost. Thanks
I Googled "CVE-2021-43893" and found the relevant page of Microsoft's Security Update Guide very quickly.
The hardest thing is deciding which download you need for your particular OS.
 
Last edited:

pascalwil

✅ Verified Member
Member
Downloaded
1.3 TB
Uploaded
36.2 TB
Ratio
28.55
Seedbonus
23,798
Upload Count
0 (0)
Member for 8 years
Thanks Charlie. That's my point. I get lost with the different versions. Hope to get some feedback from users who have installed the Medicines successfully.
With the OS version and the KB number if that's not asking too much. Some help from the geeks to the less experienced users if I may say!
 

mobi0001

The Power Is Yours!!!
Uploader
Power User
✅ Verified Member
Member
Downloaded
62.3 GB
Uploaded
11.3 TB
Ratio
186.25
Seedbonus
1,012
Upload Count
89 (104)
Member for 4 years
Thanks Charlie. That's my point. I get lost with the different versions. Hope to get some feedback from users who have installed the Medicines successfully.
With the OS version and the KB number if that's not asking too much. Some help from the geeks to the less experienced users if I may say!
Depends on your architecture of the motherboard and cpu. You can look up which one to install via your system-info and then check against the CVE details. If unsure use a 3rd party app, but then it would be easy to check via inbuilt system info.
 

pascalwil

✅ Verified Member
Member
Downloaded
1.3 TB
Uploaded
36.2 TB
Ratio
28.55
Seedbonus
23,798
Upload Count
0 (0)
Member for 8 years
Thanks for the reply. Happy new year.
 

PsyTom

Power User
✅ Verified Member
Member
Downloaded
1.4 TB
Uploaded
502.1 TB
Ratio
367.69
Seedbonus
1,662,990
Upload Count
0 (0)
Member for 3 years
thank you for sharing this update.
 
Top