SlideShare a Scribd company logo
1 of 39
Copyright © 2021 Ivanti. All rights reserved.
Patch Tuesday Webinar
Jeudi, 15 avril 2021
Eric Vincent & Camille Proux
Copyright © 2021 Ivanti. All rights reserved.
Agenda
April 2021 Patch Tuesday Overview
In the News
Bulletins and Releases
Between Patch Tuesdays
Q & A
1
2
3
4
5
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
Overview
Copyright © 2021 Ivanti. All rights reserved.
April Patch Tuesday 2021
Microsoft has released updates for the Windows OS, Office and O365, Exchange
Server, Edge (Chromium), Visual Studio, Azure DevOps, Azure AD Web Sign-in,
Azure Sphere, and many other components. A total of 110 unique vulnerabilities
have been resolved this month including one Zero Day, and four publicly disclosed
vulnerabilities. There are a lot of vulnerabilities being resolved this month. The
good news is most of them are in the OS including the Zero Day and three of four
of the Publicly Disclosed vulnerabilities. Knocking the OS out quickly will reduce a
significant amount of risk for your organization. Top priorities this month should
include the Windows OS, Edge (Chromium), and Exchange Server.
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
In the News
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
In the News
Source: Microsoft
 Pwn2Own Results – What to expect in the next 90 days
 https://www.zerodayinitiative.com/blog/2021/4/2/pwn2own-
2021-schedule-and-live-results
 FBI blasts away web shells on US servers in wake of
Exchange vulnerabilities
 https://www.zdnet.com/article/fbi-blasts-away-web-shells-on-us-
servers-in-wake-of-exchange-vulnerabilities/?&web_view=true
 RemoteFX vGPU removed from all applicable Windows
platforms this month
 https://support.microsoft.com/en-us/topic/kb4570006-update-
to-disable-and-remove-the-remotefx-vgpu-component-in-
windows-bbdf1531-7188-2bf4-0de6-641de79f09d2
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
Publicly Disclosed Vulnerabilities
 CVE-2021-27091 RPC Endpoint Mapper Service Elevation of
Privilege Vulnerability
 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-27091
 CVE-2021-28312 Windows NTFS Denial of Service Vulnerability
 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-28312
 CVE-2021-28437 Windows Installer Information Disclosure
Vulnerability
 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-28437
 CVE-2021-28458 Azure ms-rest-nodeauth Library Elevation of
Privilege Vulnerability
 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-28458
Source: Microsoft
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
Known Exploited Vulnerability
 CVE-2021-28310 Win32k Elevation of Privilege Vulnerability
 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-28310
Source: Microsoft
Affected Products: Windows 10 1803 – 20H2
Windows Server, 1909 - 2004
Severity: Critical
Base CVSS 3.0 Score: 7.8
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
Microsoft Patch Tuesday Updates of Interest
 Advisory 990001 Latest Servicing Stack Updates (SSU)
 https://msrc.microsoft.com/update-guide/en-US/vulnerability/ADV990001
 Updated SSUs this month
 See Table
 Development Tool and Other Updates
 Azure DevOps Server 2019-2020
 Azure @azure/ms-rest-nodeauth
 Azure Sphere
 Team Foundation Server 2015-2018
 Visual Studio 2015-2019
 Visual Studio Code (multiple components)
Source: Microsoft
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
Windows 10 Lifecycle Awareness
Windows 10 Enterprise and Education
Version Release Date End of Support Date
20H2 10/20/2020 5/9/2023
2004 5/27/2020 12/14/2021
1909 11/12/2019 5/10/2022
1903 5/21/2019 12/8/2020
1809 11/13/2018 5/11/2021
1803 4/30/2018 5/11/2021
1709 10/17/2017 10/13/2020
Windows Datacenter and Standard Server
Version Release Date End of Support Date
20H2 10/20/2020 5/10/2022
2004 5/27/2020 12/14/2021
1909 11/12/2019 5/11/2021
1903 5/21/2019 12/8/2020
 Lifecycle Fact Sheet
 https://docs.microsoft.com/en-us/lifecycle/faq/windows
 https://docs.microsoft.com/en-us/lifecycle/products/windows-server
 https://docs.microsoft.com/en-us/lifecycle/products/windows-10-enterprise-
and-education
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
Patch Content Announcements
 Announcements Posted on Community Forum Pages
 https://forums.ivanti.com/s/group/CollaborationGroup/00Ba0000009oKICEA2
 Subscribe to receive email for the desired product(s)
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
Bulletins and Releases
Copyright © 2021 Ivanti. All rights reserved.
MS21-04-W10: Windows 10 Update
 Maximum Severity: Critical
 Affected Products: Microsoft Windows 10 Versions 1607, 1709, 1803, 1809, 1903,
1909, 2004, 20H2, Server 2016, Server 2019, Server version 1909, Server version
2004, Server version 20H2, IE 11, Legacy Edge and Edge Chromium
 Description: This bulletin references 6 KB articles. See KBs for the list of changes.
 Impact: Remote Code Execution, Security Feature Bypass, Spoofing, Denial of
Service, Elevation of Privilege and Information Disclosure
 Fixes 79 Vulnerabilities: CVE-2021-28312 and CVE-2021-28437 are publicly
disclosed. CVE-2021-28310 is known exploited. See the Security Update Guide for
the complete list of CVEs.
 Restart Required: Requires restart
 Known Issues: See next slides
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
April Known Issues for Windows 10
 KB 5001347 – Windows 10, Version 1607 and Server 2016
 [Min Password] After installing KB4467684, the cluster service may fail to start with
the error “2245 (NERR_PasswordTooShort)” if the group policy “Minimum
Password Length” is configured with greater than 14 characters. Workaround:
Set the domain default "Minimum Password Length" policy to less than or equal to
14 characters. Microsoft is working on a resolution.
 KB 5001342 – Windows 10, Version 1809, Server 2019
 [Asian Packs] After installing KB 4493509, devices with some Asian language
packs installed may receive the error, "0x800f0982 -
PSFX_E_MATCHING_COMPONENT_NOT_FOUND.“ Workaround: Uninstall
and reinstall any recently added language packs or select Check for Updates and
install the April 2019 Cumulative Update. See KB for more recovery details.
Microsoft is working on a resolution.
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
April Known Issues for Windows 10 (cont)
 KB 5001337 – Windows 10 version 1909, Windows Server version 1909
 [Outdated Updates] System and user certificates might be lost when updating a
device from Windows 10, version 1809 or later to a later version of Windows 10.
This primarily happens when managed devices are updated using outdated
bundles or media through an update management tool such as Windows Server
Update Services (WSUS) or Microsoft Endpoint Configuration Manager.
Note: Devices using Windows Update for Business or that connect directly to
Windows Update are not impacted.
Workaround: If you have already encountered this issue on your device, you can
mitigate it within the uninstall window by going back to your previous version of
Windows. The uninstall window might be 10 or 30 days depending on the
configuration of your environment and the version you’re updating to. See
directions here.
Microsoft is working on a resolution.
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
April Known Issues for Windows 10 (cont)
 KB 5001330 – Windows 10 version 2004, Windows Server version
2004, Windows 10 version 20H2, Windows Server version 20H2
 [Editor] When using the Microsoft Japanese Input Method Editor (IME) to enter
Kanji characters in an app that automatically allows the input of Furigana
characters, you might not get the correct Furigana characters. You might need to
enter the Furigana characters manually. Workaround: Microsoft is working on a
resolution.
 [Outdated Updates]
Copyright © 2021 Ivanti. All rights reserved.
MS21-04-MR2K8-ESU: Monthly Rollup for Windows Server 2008
 Maximum Severity: Critical
 Affected Products: Microsoft Windows Server 2008 and IE 9
 Description: This security update includes improvements and fixes that were a part
of update KB 5000844 (released March 9, 2021). Bulletin is based on KB 5001389.
Security updates to Windows Apps, Windows Hybrid Cloud Networking, Windows
Kernel, and Windows Media.
 Impact: Remote Code Execution, Spoofing, Denial of Service, Elevation of Privilege
and Information Disclosure
 Fixes 47 Vulnerabilities: CVE-2021-28437 is publicly disclosed. See the Security
Update Guide for the complete list of CVEs.
 Restart Required: Requires restart
 Known Issues: [File Rename] See next slide.
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
April Known Issues for Server 2008
 KB 5001389 – Windows Server 2008 (Monthly Rollup)
 [File Rename] Certain operations, such as rename, that you perform on files or folders that
are on a Cluster Shared Volume (CSV) may fail with the error,
“STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)”. This occurs when you perform
the operation on a CSV owner node from a process that doesn’t have administrator
privilege. Workaround: Perform the operation from a process that has administrator
privilege or perform the operation from a node that doesn’t have CSV ownership. Microsoft
is working on a resolution.
 KB 5001332 – Windows Server 2008 (Security-only Update)
 [File Rename]
Copyright © 2021 Ivanti. All rights reserved.
MS21-04-SO2K8-ESU: Security-only Update for Windows Server 2008
 Maximum Severity: Critical
 Affected Products: Microsoft Windows Server 2008
 Description: Bulletin is based on KB 5001332. Security updates to Windows Apps,
Windows Hybrid Cloud Networking, Windows Kernel, and Windows Media.
 Impact: Remote Code Execution, Spoofing, Denial of Service, Elevation of Privilege
and Information Disclosure
 Fixes 47 Vulnerabilities: CVE-2021-28437 is publicly disclosed. No CVEs are
known exploited. See the Security Update Guide for the complete list of CVEs.
 Restart Required: Requires restart
 Known Issues: [File Rename] See previous slide.
Copyright © 2021 Ivanti. All rights reserved.
MS21-04-MR7-ESU: Monthly Rollup for Win 7
MS21-04-MR2K8R2-ESU Monthly Rollup for Server 2008 R2
 Maximum Severity: Critical
 Affected Products: Microsoft Windows 7, Server 2008 R2, and IE
 Description: This security update includes improvements and fixes that were a part
of update KB 5000841 (released March 9, 2021). Bulletin is based on KB 5001335.
RemoteFX vGPU feature removed from codebase. Security updates to Windows Apps,
Windows Hybrid Cloud Networking, Windows Kernel, and Windows Media.
 Impact: Remote Code Execution, Security Feature Bypass, Spoofing, Denial of
Service, Elevation of Privilege and Information Disclosure
 Fixes 50 Vulnerabilities: CVE-2021-27091 and CVE-2020-28437 are publicly
disclosed. See the Security Update Guide for the complete list of CVEs.
 Restart Required: Requires restart
 Known Issues: [File Rename]
Copyright © 2021 Ivanti. All rights reserved.
MS21-04-SO7-ESU: Security-only Update for Win 7
MS21-04-SO2K8R2-ESU: Security-only Update for Server 2008 R2
 Maximum Severity: Critical
 Affected Products: Microsoft Windows 7 and Server 2008 R2
 Description: Bulletin is based on KB 5001392. Security updates to Windows Apps,
Windows Hybrid Cloud Networking, and Windows Media.
 Impact: Remote Code Execution, Security Feature Bypass, Spoofing, Denial of
Service, Elevation of Privilege and Information Disclosure
 Fixes 50 Vulnerabilities: CVE-2021-27091 and CVE-2020-28437 are publicly
disclosed. See the Security Update Guide for the complete list of CVEs.
 Restart Required: Requires restart
 Known Issues: [File Rename]
Copyright © 2021 Ivanti. All rights reserved.
MS21-04-MR8: Monthly Rollup for Server 2012
 Maximum Severity: Critical
 Affected Products: Microsoft Windows Server 2012 and IE
 Description: This security update includes improvements and fixes that were a part of
update KB 5000847 (released March 9, 2021). Bulletin is based on KB 5001387.
RemoteFX vGPU feature removed from codebase. Security updates to Windows Apps,
Windows Input and Composition, Windows Hybrid Cloud Networking, Windows Kernel,
and Windows Media.
 Impact: Remote Code Execution, Security Feature Bypass, Spoofing, Denial of Service,
Elevation of Privilege and Information Disclosure
 Fixes 54 Vulnerabilities: CVE-2021-27091 and CVE-2020-28437 are publicly
disclosed. See the Security Update Guide for the complete list of CVEs.
 Restart Required: Requires restart
 Known Issues: [File Rename]
Copyright © 2021 Ivanti. All rights reserved.
MS21-04-SO8: Security-only Update for Windows Server 2012
 Maximum Severity: Critical
 Affected Products: Microsoft Windows Server 2012
 Description: Bulletin is based on KB 5001383. Security updates to Windows Apps,
Windows Input and Composition, Windows Hybrid Cloud Networkin2, Windows Kernel,
and Windows Media.
 Impact: Remote Code Execution, Security Feature Bypass, Spoofing, Denial of
Service, Elevation of Privilege and Information Disclosure
 Fixes 54 Vulnerabilities: CVE-2021-27091 and CVE-2020-28437 are publicly
disclosed. See the Security Update Guide for the complete list of CVEs.
 Restart Required: Requires restart
 Known Issues: [File Rename]
Copyright © 2021 Ivanti. All rights reserved.
MS21-04-MR81: Monthly Rollup for Win 8.1 and Server 2012 R2
 Maximum Severity: Critical
 Affected Products: Microsoft Windows 8.1, Server 2012 R2, and IE
 Description: This security update includes improvements and fixes that were a part
of update KB 5000848 (released March 9, 2021). Bulletin is based on KB 5001382.
RemoteFX vGPU feature removed from codebase. Security updates to Windows Input
and Composition, Windows Fundamentals, Windows Hybrid Cloud Networking,
Windows Kernel, and Windows Media.
 Impact: Remote Code Execution, Security Feature Bypass, Spoofing, Denial of
Service, Elevation of Privilege and Information Disclosure
 Fixes 55 Vulnerabilities: CVE-2020-28437 is publicly disclosed. See the Security
Update Guide for the complete list of CVEs.
 Restart Required: Requires restart
 Known Issues: [File Rename]
Copyright © 2021 Ivanti. All rights reserved.
MS21-04-SO81: Security-only Update for Win 8.1 and Server 2012 R2
 Maximum Severity: Critical
 Affected Products: Microsoft Windows 8.1, Server 2012 R2
 Description: Bulletin is based on KB 5001393. Security updates to Windows Input
and Composition, Windows Fundamentals, Windows Hybrid Cloud Networking,
Windows Kernel, and Windows Media.
 Impact: Remote Code Execution, Security Feature Bypass, Spoofing, Denial of
Service, Elevation of Privilege and Information Disclosure
 Fixes 55 Vulnerabilities: CVE-2020-28437 is publicly disclosed. See the Security
Update Guide for the complete list of CVEs.
 Restart Required: Requires restart
 Known Issues: [File Rename]
Copyright © 2020 Ivanti. All rights reserved.
MS21-04-EXCH: Security Updates for Exchange Server
 Maximum Severity: Critical
 Affected Products: Microsoft Exchange Server 2013 - 2019
 Description: This security update fixes vulnerabilities in Microsoft
Exchange. This bulletin is based on KB 5001779.
 Impact: Remote Code Execution
 Fixes 4 Vulnerabilities: No CVEs are publicly disclosed or known
exploited. CVE-2021-28480, CVE-2021-28481, CVE-2021-28482,
and CVE-2021-28483 are fixed in this release.
 Restart Required: Requires restart
 Known Issues: Must install update with administrator privileges
Copyright © 2021 Ivanti. All rights reserved.
MS21-04-OFF: Security Updates for Microsoft Office
 Maximum Severity: Important
 Affected Products: Excel 2010-2016, Office 2010-2016, Office 2019 for macOS,
Office Online Server, Office Web Apps 2010 and 2013, Outlook 2010-2016, Word
2010-2016.
 Description: This security update resolves multiple vulnerabilities in Microsoft Office
applications. Consult the Security Update Guide for specific details on each. This
bulletin references 23 KB articles plus release notes for the macOS Office.
 Impact: Remote Code Execution and Information Disclosure
 Fixes 6 Vulnerabilities: No vulnerabilities are publicly disclosed or known
exploited. CVE-2021-28449, CVE-2021-28451, CVE-2021-28452, CVE-2021-28453,
CVE-2021-28454, and CVE-2021-28456 are fixed in this release.
 Restart Required: Requires application restart
 Known Issues: None reported
Copyright © 2021 Ivanti. All rights reserved.
MS21-04-O365: Security Updates Microsoft 365 Apps and Office 2019
 Maximum Severity: Important
 Affected Products: Microsoft 365 Apps, Office 2019
 Description: This month’s update resolved various bugs and performance issues in
Microsoft 365 Apps and Office 2019 applications. Information on Microsoft 365 Apps
security updates is available at https://docs.microsoft.com/en-
us/officeupdates/microsoft365-apps-security-updates.
 Impact: Remote Code Execution and Information Disclosure
 Fixes 6 Vulnerabilities: No vulnerabilities are publicly disclosed or known
exploited. CVE-2021-28449, CVE-2021-28451, CVE-2021-28452, CVE-2021-28453,
CVE-2021-28454, and CVE-2021-28456 are fixed in this release.
 Restart Required: Requires application restart
 Known Issues: None reported
Copyright © 2021 Ivanti. All rights reserved.
MS21-04-SPT: Security Updates for SharePoint Server
 Maximum Severity: Important
 Affected Products: Microsoft SharePoint Server 2010, Microsoft SharePoint
Foundation Server 2013, Microsoft SharePoint Enterprise Server 2016, and Microsoft
SharePoint Server 2019
 Description: This security update resolves vulnerabilities in Microsoft Office that
could allow remote code execution if a user opens a specially crafted Office file. This
bulletin is based on 8 KB articles.
 Impact: Remote Code Execution and Denial of Service
 Fixes 2 Vulnerabilities: No CVEs are publicly disclosed or known exploited. CVE-
2021-28450 and CVE-2021-28453 are fixed in this release.
 Restart Required: Requires restart
 Known Issues: None reported
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
Between Patch Tuesdays
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
Release Summary
 Security Updates: Google Chrome (2), Firefox (1), Firefox ESR (1), Cisco Jabber
(1), Node.JS (4), SeaMonkey (1), Thunderbird (2), VMware Horizon Client (1),
Wireshark (2)
 Non-Security Updates: AIMP (1), Allway Sync (1), Adobe Acrobat and Reader (1),
Audacity (1), Bandicut (2), Box Edit (1), CCleaner (1), ClickShare (1), Falcon sensor for
Window (2), Citrix Workspace App (2), CutePDF Writer (1), DropBox (2), Evernote (2),
Firefox (1), Foxit Reader (1), FileZilla Client (2), Foxit PhantomPDF (1), GoodSync (8),
GIMP (1), GIT for windows (2), Google Backup and Sync (1), Cisco Jabber (1),
BlueJeans (1), LibreOffice (2), LogMeIn (1), Malwarebytes (1), Nitro Pro (2), Node.JS (3),
Notepad (2), Opera (5), Pidgin (2), Plex Media Server (4), PSPad (1), PeaZip (1), R for
Windows (1), RingCentral App (1), RedHat OpenJDK (3), Royal TS (2), RealVNC Server
(1), Slack Machine-Wide Installer (1), Snagit (1), Splunk Universal Forwarder (1),
Sourcetree (1), Tableau Desktop (9), Tableau Reader (2), TortoiseGit (1), TortoiseHG (1),
Apache Tomcat (4), TeamViewer (7), VMware Horizon Client (2), VMware Workstation
(1), Cisco WebEx Teams (2), Zoom Client (2), Zoom Outlook Plugin (2)
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
Third Party CVE Information (cont)
 Cisco Jabber 12.9.5.305511
 JABBER-210201, QJABBER1295305511
 Fixes 5 Vulnerabilities: CVE-2021-1411, CVE-2021-1417, CVE-2021-1418, CVE-
2021-1469, CVE-2021-1471
 Google Chrome 89.0.4389.90
 CHROME-210312, QGC890438990
 Fixes 3 Vulnerabilities: CVE-2021-21191, CVE-2021-21192, CVE-2021-21193
 Google Chrome 89.0.4389.114
 CHROME-2103312, QGC8904389114
 Fixes 6 Vulnerabilities: CVE-2021-21194, CVE-2021-21195, CVE-2021-21196,
CVE-2021-21197, CVE-2021-21198, CVE-2021-21199
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
Third Party CVE Information
 Firefox 87.0
 FF-210323, QFF870
 Fixes 8 Vulnerabilities: CVE-2021-23981, CVE-2021-23982, CVE-2021-23983,
CVE-2021-23984, CVE-2021-23985, CVE-2021-23986, CVE-2021-23987, CVE-
2021-23988
 Firefox ESR 78.9.0
 FFE-210323, QFFE7890
 Fixes 4 Vulnerabilities: CVE-2021-23981, CVE-2021-23982, CVE-2021-23984,
CVE-2021-23987
 VMware Horizon Client 5.5.1
 VMWH5-210323, QVMWH551
 Fixes 1 Vulnerability: CVE-2020-3991
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
Third Party CVE Information
 Node.JS 15.14.0 (Current)
 NOJSC-210406, QNODEJSC15140
 Fixes 3 Vulnerabilities: CVE-2021-3449, CVE-2021-3450, CVE-2021-7774
 Node.JS 12.22.1 (LTS Lower)
 NOJSLL-210406, QNODEJSLL12221
 Fixes 3 Vulnerabilities: CVE-2021-3449, CVE-2021-3450, CVE-2021-7774
 Node.JS 14.16.1 (LTS Upper)
 NOJSLU-210406, QNODEJSLU14161
 Fixes 3 Vulnerabilities: CVE-2021-3449, CVE-2021-3450, CVE-2021-7774
 Node.JS 10.24.1 (Maintain)
 NOJSM-210406, QNODEJSLL10241
 Fixes 3 Vulnerabilities: CVE-2021-3449, CVE-2021-3450, CVE-2021-7774
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
Third Party CVE Information (cont)
 SeaMonkey 2.53.7
 SM20-210330, QSM2537
 Fixes 14 Vulnerabilities: CVE-2018-12359, CVE-2018-12360, CVE-2018-12361,
CVE-2018-12362, CVE-2018-12363, CVE-2018-12364, CVE-2018-12365, CVE-
2018-12366, CVE-2018-12367, CVE-2018-12368, CVE-2018-12371, CVE-2018-
5156, CVE-2018-5187, CVE-2018-5188
 Thunderbird 78.9.0
 TB-210325, QTB7890
 Fixes 4 Vulnerabilities: CVE-2021-23981, CVE-2021-23982, CVE-2021-23984,
CVE-2021-23987
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
Third Party CVE Information (cont)
 Thunderbird 78.9.1
 TB-210409, QTB7891
 Fixes 2 Vulnerabilities: CVE-2021-23991, CVE-2021-23993
 Wireshark 3.2.12
 WIRES32-210311, QWIRES3212
 Fixes 1 Vulnerability: CVE-2021-22191
 Wireshark 3.4.4
 WIRES32-210311, QWIRES344
 Fixes 1 Vulnerability: CVE-2021-22191
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
Q & A
Copyright © 2021 Ivanti. All rights reserved.
Copyright © 2021 Ivanti. All rights reserved.
Prochain Rendez-Vous Patch Tuesday
 Mardi 18 mai – 16h00
 Jeudi 10 juin – 16h00
 Mardi 20 juillet – 16h00
 Jeudi 12 août – 16h00
 Jeudi 16 septembre – 16h00
https://www.ivanti.fr/resources/patch-tuesday
Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved.
Thank You!

More Related Content

What's hot

August 2021 Patch Tuesday slides - French
August 2021 Patch Tuesday slides - FrenchAugust 2021 Patch Tuesday slides - French
August 2021 Patch Tuesday slides - FrenchIvanti
 
2021 November Patch Tuesday
2021 November Patch Tuesday2021 November Patch Tuesday
2021 November Patch TuesdayIvanti
 
2021 September Patch Tuesday
2021 September Patch Tuesday2021 September Patch Tuesday
2021 September Patch TuesdayIvanti
 
February 2021 Patch Tuesday
February 2021 Patch TuesdayFebruary 2021 Patch Tuesday
February 2021 Patch TuesdayIvanti
 
December Patch Tuesday 2020
December Patch Tuesday 2020December Patch Tuesday 2020
December Patch Tuesday 2020Ivanti
 
Ivanti Patch Tuesday for October 2019
Ivanti Patch Tuesday for October 2019Ivanti Patch Tuesday for October 2019
Ivanti Patch Tuesday for October 2019Ivanti
 
January 2021 Patch Tuesday
January 2021 Patch TuesdayJanuary 2021 Patch Tuesday
January 2021 Patch TuesdayIvanti
 
Fr mar 2022 patch tuesday-presenters slides
Fr mar 2022 patch tuesday-presenters slidesFr mar 2022 patch tuesday-presenters slides
Fr mar 2022 patch tuesday-presenters slidesIvanti
 
Ivanti Patch Tuesday for April 2020
Ivanti Patch Tuesday for April 2020Ivanti Patch Tuesday for April 2020
Ivanti Patch Tuesday for April 2020Ivanti
 
2022 March Patch Tuesday
2022 March Patch Tuesday2022 March Patch Tuesday
2022 March Patch TuesdayIvanti
 
2022 February Patch Tuesday
2022 February Patch Tuesday2022 February Patch Tuesday
2022 February Patch TuesdayIvanti
 
December 2021 patch tuesday
December 2021 patch tuesdayDecember 2021 patch tuesday
December 2021 patch tuesdayIvanti
 
Fr february 2022 patch tuesday v2 presenters slides
Fr february 2022 patch tuesday v2   presenters slidesFr february 2022 patch tuesday v2   presenters slides
Fr february 2022 patch tuesday v2 presenters slidesIvanti
 
February Patch Tuesday 2019
February Patch Tuesday 2019February Patch Tuesday 2019
February Patch Tuesday 2019Ivanti
 
January Patch Tuesday 2019
January Patch Tuesday 2019January Patch Tuesday 2019
January Patch Tuesday 2019Ivanti
 
January 2022 patch tuesday
January 2022 patch tuesdayJanuary 2022 patch tuesday
January 2022 patch tuesdayIvanti
 
November Patch Tuesday Analysis
November Patch Tuesday AnalysisNovember Patch Tuesday Analysis
November Patch Tuesday AnalysisIvanti
 
October2020 patchtuesday[1] read-only
October2020 patchtuesday[1]     read-onlyOctober2020 patchtuesday[1]     read-only
October2020 patchtuesday[1] read-onlyIvanti
 
December 2018 Patch Tuesday Analysis
December 2018 Patch Tuesday AnalysisDecember 2018 Patch Tuesday Analysis
December 2018 Patch Tuesday AnalysisIvanti
 
October Patch Tuesday Analysis 2018
October Patch Tuesday Analysis 2018October Patch Tuesday Analysis 2018
October Patch Tuesday Analysis 2018Ivanti
 

What's hot (20)

August 2021 Patch Tuesday slides - French
August 2021 Patch Tuesday slides - FrenchAugust 2021 Patch Tuesday slides - French
August 2021 Patch Tuesday slides - French
 
2021 November Patch Tuesday
2021 November Patch Tuesday2021 November Patch Tuesday
2021 November Patch Tuesday
 
2021 September Patch Tuesday
2021 September Patch Tuesday2021 September Patch Tuesday
2021 September Patch Tuesday
 
February 2021 Patch Tuesday
February 2021 Patch TuesdayFebruary 2021 Patch Tuesday
February 2021 Patch Tuesday
 
December Patch Tuesday 2020
December Patch Tuesday 2020December Patch Tuesday 2020
December Patch Tuesday 2020
 
Ivanti Patch Tuesday for October 2019
Ivanti Patch Tuesday for October 2019Ivanti Patch Tuesday for October 2019
Ivanti Patch Tuesday for October 2019
 
January 2021 Patch Tuesday
January 2021 Patch TuesdayJanuary 2021 Patch Tuesday
January 2021 Patch Tuesday
 
Fr mar 2022 patch tuesday-presenters slides
Fr mar 2022 patch tuesday-presenters slidesFr mar 2022 patch tuesday-presenters slides
Fr mar 2022 patch tuesday-presenters slides
 
Ivanti Patch Tuesday for April 2020
Ivanti Patch Tuesday for April 2020Ivanti Patch Tuesday for April 2020
Ivanti Patch Tuesday for April 2020
 
2022 March Patch Tuesday
2022 March Patch Tuesday2022 March Patch Tuesday
2022 March Patch Tuesday
 
2022 February Patch Tuesday
2022 February Patch Tuesday2022 February Patch Tuesday
2022 February Patch Tuesday
 
December 2021 patch tuesday
December 2021 patch tuesdayDecember 2021 patch tuesday
December 2021 patch tuesday
 
Fr february 2022 patch tuesday v2 presenters slides
Fr february 2022 patch tuesday v2   presenters slidesFr february 2022 patch tuesday v2   presenters slides
Fr february 2022 patch tuesday v2 presenters slides
 
February Patch Tuesday 2019
February Patch Tuesday 2019February Patch Tuesday 2019
February Patch Tuesday 2019
 
January Patch Tuesday 2019
January Patch Tuesday 2019January Patch Tuesday 2019
January Patch Tuesday 2019
 
January 2022 patch tuesday
January 2022 patch tuesdayJanuary 2022 patch tuesday
January 2022 patch tuesday
 
November Patch Tuesday Analysis
November Patch Tuesday AnalysisNovember Patch Tuesday Analysis
November Patch Tuesday Analysis
 
October2020 patchtuesday[1] read-only
October2020 patchtuesday[1]     read-onlyOctober2020 patchtuesday[1]     read-only
October2020 patchtuesday[1] read-only
 
December 2018 Patch Tuesday Analysis
December 2018 Patch Tuesday AnalysisDecember 2018 Patch Tuesday Analysis
December 2018 Patch Tuesday Analysis
 
October Patch Tuesday Analysis 2018
October Patch Tuesday Analysis 2018October Patch Tuesday Analysis 2018
October Patch Tuesday Analysis 2018
 

Similar to French Patch Tuesday April 2021

2021 October Patch Tuesday
2021 October Patch Tuesday2021 October Patch Tuesday
2021 October Patch TuesdayIvanti
 
2021 August Patch Tuesday
2021 August Patch Tuesday2021 August Patch Tuesday
2021 August Patch TuesdayIvanti
 
Janvier2023PatchTuesday - Presenter slides.pptx
Janvier2023PatchTuesday - Presenter slides.pptxJanvier2023PatchTuesday - Presenter slides.pptx
Janvier2023PatchTuesday - Presenter slides.pptxIvanti
 
2022 August Patch Tuesday
2022 August Patch Tuesday2022 August Patch Tuesday
2022 August Patch TuesdayIvanti
 
2022 June FR Patch Tuesday
2022 June FR Patch Tuesday2022 June FR Patch Tuesday
2022 June FR Patch TuesdayIvanti
 
2022 June Patch Tuesday
2022 June Patch Tuesday2022 June Patch Tuesday
2022 June Patch TuesdayIvanti
 
2022 October Patch Tuesday
2022 October Patch Tuesday2022 October Patch Tuesday
2022 October Patch TuesdayIvanti
 
2022 Novembre Patch Tuesday
2022 Novembre Patch Tuesday2022 Novembre Patch Tuesday
2022 Novembre Patch TuesdayIvanti
 
2022 FR April Patch Tuesday
2022 FR April Patch Tuesday2022 FR April Patch Tuesday
2022 FR April Patch TuesdayIvanti
 
2023 January Patch Tuesday
2023 January Patch Tuesday2023 January Patch Tuesday
2023 January Patch TuesdayIvanti
 
2022 April Patch Tuesday
2022 April Patch Tuesday2022 April Patch Tuesday
2022 April Patch TuesdayIvanti
 
2022 FR Patch Tuesday.pptx
2022 FR Patch Tuesday.pptx2022 FR Patch Tuesday.pptx
2022 FR Patch Tuesday.pptxIvanti
 
2022 May Patch Tuesday
2022 May Patch Tuesday2022 May Patch Tuesday
2022 May Patch TuesdayIvanti
 
2022 September Patch Tuesday
2022 September Patch Tuesday2022 September Patch Tuesday
2022 September Patch TuesdayIvanti
 
2022 November Patch Tuesday
2022 November Patch Tuesday2022 November Patch Tuesday
2022 November Patch TuesdayIvanti
 
March 2018 Patch Tuesday Ivanti
March 2018 Patch Tuesday IvantiMarch 2018 Patch Tuesday Ivanti
March 2018 Patch Tuesday IvantiIvanti
 
2023 April Patch Tuesday
2023 April Patch Tuesday2023 April Patch Tuesday
2023 April Patch TuesdayIvanti
 
2023 Mars Patch Tuesday
2023 Mars Patch Tuesday2023 Mars Patch Tuesday
2023 Mars Patch TuesdayIvanti
 
2023 March Patch Tuesday
2023 March Patch Tuesday2023 March Patch Tuesday
2023 March Patch TuesdayIvanti
 
Analyse Patch Tuesday - mai
Analyse Patch Tuesday - maiAnalyse Patch Tuesday - mai
Analyse Patch Tuesday - maiIvanti
 

Similar to French Patch Tuesday April 2021 (20)

2021 October Patch Tuesday
2021 October Patch Tuesday2021 October Patch Tuesday
2021 October Patch Tuesday
 
2021 August Patch Tuesday
2021 August Patch Tuesday2021 August Patch Tuesday
2021 August Patch Tuesday
 
Janvier2023PatchTuesday - Presenter slides.pptx
Janvier2023PatchTuesday - Presenter slides.pptxJanvier2023PatchTuesday - Presenter slides.pptx
Janvier2023PatchTuesday - Presenter slides.pptx
 
2022 August Patch Tuesday
2022 August Patch Tuesday2022 August Patch Tuesday
2022 August Patch Tuesday
 
2022 June FR Patch Tuesday
2022 June FR Patch Tuesday2022 June FR Patch Tuesday
2022 June FR Patch Tuesday
 
2022 June Patch Tuesday
2022 June Patch Tuesday2022 June Patch Tuesday
2022 June Patch Tuesday
 
2022 October Patch Tuesday
2022 October Patch Tuesday2022 October Patch Tuesday
2022 October Patch Tuesday
 
2022 Novembre Patch Tuesday
2022 Novembre Patch Tuesday2022 Novembre Patch Tuesday
2022 Novembre Patch Tuesday
 
2022 FR April Patch Tuesday
2022 FR April Patch Tuesday2022 FR April Patch Tuesday
2022 FR April Patch Tuesday
 
2023 January Patch Tuesday
2023 January Patch Tuesday2023 January Patch Tuesday
2023 January Patch Tuesday
 
2022 April Patch Tuesday
2022 April Patch Tuesday2022 April Patch Tuesday
2022 April Patch Tuesday
 
2022 FR Patch Tuesday.pptx
2022 FR Patch Tuesday.pptx2022 FR Patch Tuesday.pptx
2022 FR Patch Tuesday.pptx
 
2022 May Patch Tuesday
2022 May Patch Tuesday2022 May Patch Tuesday
2022 May Patch Tuesday
 
2022 September Patch Tuesday
2022 September Patch Tuesday2022 September Patch Tuesday
2022 September Patch Tuesday
 
2022 November Patch Tuesday
2022 November Patch Tuesday2022 November Patch Tuesday
2022 November Patch Tuesday
 
March 2018 Patch Tuesday Ivanti
March 2018 Patch Tuesday IvantiMarch 2018 Patch Tuesday Ivanti
March 2018 Patch Tuesday Ivanti
 
2023 April Patch Tuesday
2023 April Patch Tuesday2023 April Patch Tuesday
2023 April Patch Tuesday
 
2023 Mars Patch Tuesday
2023 Mars Patch Tuesday2023 Mars Patch Tuesday
2023 Mars Patch Tuesday
 
2023 March Patch Tuesday
2023 March Patch Tuesday2023 March Patch Tuesday
2023 March Patch Tuesday
 
Analyse Patch Tuesday - mai
Analyse Patch Tuesday - maiAnalyse Patch Tuesday - mai
Analyse Patch Tuesday - mai
 

More from Ivanti

2024 April Patch Tuesday
2024 April Patch Tuesday2024 April Patch Tuesday
2024 April Patch TuesdayIvanti
 
Patch Tuesday de Abril
Patch Tuesday de AbrilPatch Tuesday de Abril
Patch Tuesday de AbrilIvanti
 
Français Patch Tuesday - Avril
Français Patch Tuesday - AvrilFrançais Patch Tuesday - Avril
Français Patch Tuesday - AvrilIvanti
 
Patch Tuesday Italia Aprile
Patch Tuesday Italia AprilePatch Tuesday Italia Aprile
Patch Tuesday Italia AprileIvanti
 
Français Patch Tuesday - Mars
Français Patch Tuesday - MarsFrançais Patch Tuesday - Mars
Français Patch Tuesday - MarsIvanti
 
Patch Tuesday de Marzo
Patch Tuesday de MarzoPatch Tuesday de Marzo
Patch Tuesday de MarzoIvanti
 
Patch Tuesday Italia Marzo
Patch Tuesday Italia MarzoPatch Tuesday Italia Marzo
Patch Tuesday Italia MarzoIvanti
 
March Patch Tuesday
March Patch TuesdayMarch Patch Tuesday
March Patch TuesdayIvanti
 
Patch Tuesday de Febrero
Patch Tuesday de FebreroPatch Tuesday de Febrero
Patch Tuesday de FebreroIvanti
 
2024 Français Patch Tuesday - Février
2024 Français Patch Tuesday - Février2024 Français Patch Tuesday - Février
2024 Français Patch Tuesday - FévrierIvanti
 
Patch Tuesday Italia Febbraio
Patch Tuesday Italia FebbraioPatch Tuesday Italia Febbraio
Patch Tuesday Italia FebbraioIvanti
 
2024 February Patch Tuesday
2024 February Patch Tuesday2024 February Patch Tuesday
2024 February Patch TuesdayIvanti
 
2024 Enero Patch Tuesday
2024 Enero Patch Tuesday2024 Enero Patch Tuesday
2024 Enero Patch TuesdayIvanti
 
2024 Janvier Patch Tuesday
2024 Janvier Patch Tuesday2024 Janvier Patch Tuesday
2024 Janvier Patch TuesdayIvanti
 
2024 Gennaio Patch Tuesday
2024 Gennaio Patch Tuesday2024 Gennaio Patch Tuesday
2024 Gennaio Patch TuesdayIvanti
 
Patch Tuesday de Enero
Patch Tuesday de EneroPatch Tuesday de Enero
Patch Tuesday de EneroIvanti
 
Français Patch Tuesday – Janvier
Français Patch Tuesday – JanvierFrançais Patch Tuesday – Janvier
Français Patch Tuesday – JanvierIvanti
 
2024 January Patch Tuesday
2024 January Patch Tuesday2024 January Patch Tuesday
2024 January Patch TuesdayIvanti
 
Patch Tuesday de Diciembre
Patch Tuesday de DiciembrePatch Tuesday de Diciembre
Patch Tuesday de DiciembreIvanti
 
Français Patch Tuesday – Décembre
Français Patch Tuesday – DécembreFrançais Patch Tuesday – Décembre
Français Patch Tuesday – DécembreIvanti
 

More from Ivanti (20)

2024 April Patch Tuesday
2024 April Patch Tuesday2024 April Patch Tuesday
2024 April Patch Tuesday
 
Patch Tuesday de Abril
Patch Tuesday de AbrilPatch Tuesday de Abril
Patch Tuesday de Abril
 
Français Patch Tuesday - Avril
Français Patch Tuesday - AvrilFrançais Patch Tuesday - Avril
Français Patch Tuesday - Avril
 
Patch Tuesday Italia Aprile
Patch Tuesday Italia AprilePatch Tuesday Italia Aprile
Patch Tuesday Italia Aprile
 
Français Patch Tuesday - Mars
Français Patch Tuesday - MarsFrançais Patch Tuesday - Mars
Français Patch Tuesday - Mars
 
Patch Tuesday de Marzo
Patch Tuesday de MarzoPatch Tuesday de Marzo
Patch Tuesday de Marzo
 
Patch Tuesday Italia Marzo
Patch Tuesday Italia MarzoPatch Tuesday Italia Marzo
Patch Tuesday Italia Marzo
 
March Patch Tuesday
March Patch TuesdayMarch Patch Tuesday
March Patch Tuesday
 
Patch Tuesday de Febrero
Patch Tuesday de FebreroPatch Tuesday de Febrero
Patch Tuesday de Febrero
 
2024 Français Patch Tuesday - Février
2024 Français Patch Tuesday - Février2024 Français Patch Tuesday - Février
2024 Français Patch Tuesday - Février
 
Patch Tuesday Italia Febbraio
Patch Tuesday Italia FebbraioPatch Tuesday Italia Febbraio
Patch Tuesday Italia Febbraio
 
2024 February Patch Tuesday
2024 February Patch Tuesday2024 February Patch Tuesday
2024 February Patch Tuesday
 
2024 Enero Patch Tuesday
2024 Enero Patch Tuesday2024 Enero Patch Tuesday
2024 Enero Patch Tuesday
 
2024 Janvier Patch Tuesday
2024 Janvier Patch Tuesday2024 Janvier Patch Tuesday
2024 Janvier Patch Tuesday
 
2024 Gennaio Patch Tuesday
2024 Gennaio Patch Tuesday2024 Gennaio Patch Tuesday
2024 Gennaio Patch Tuesday
 
Patch Tuesday de Enero
Patch Tuesday de EneroPatch Tuesday de Enero
Patch Tuesday de Enero
 
Français Patch Tuesday – Janvier
Français Patch Tuesday – JanvierFrançais Patch Tuesday – Janvier
Français Patch Tuesday – Janvier
 
2024 January Patch Tuesday
2024 January Patch Tuesday2024 January Patch Tuesday
2024 January Patch Tuesday
 
Patch Tuesday de Diciembre
Patch Tuesday de DiciembrePatch Tuesday de Diciembre
Patch Tuesday de Diciembre
 
Français Patch Tuesday – Décembre
Français Patch Tuesday – DécembreFrançais Patch Tuesday – Décembre
Français Patch Tuesday – Décembre
 

Recently uploaded

The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure servicePooja Nehwal
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersThousandEyes
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxKatpro Technologies
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Alan Dix
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAndikSusilo4
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 

Recently uploaded (20)

The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping Elbows
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & Application
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 

French Patch Tuesday April 2021

  • 1. Copyright © 2021 Ivanti. All rights reserved. Patch Tuesday Webinar Jeudi, 15 avril 2021 Eric Vincent & Camille Proux
  • 2. Copyright © 2021 Ivanti. All rights reserved. Agenda April 2021 Patch Tuesday Overview In the News Bulletins and Releases Between Patch Tuesdays Q & A 1 2 3 4 5
  • 3. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. Overview
  • 4. Copyright © 2021 Ivanti. All rights reserved. April Patch Tuesday 2021 Microsoft has released updates for the Windows OS, Office and O365, Exchange Server, Edge (Chromium), Visual Studio, Azure DevOps, Azure AD Web Sign-in, Azure Sphere, and many other components. A total of 110 unique vulnerabilities have been resolved this month including one Zero Day, and four publicly disclosed vulnerabilities. There are a lot of vulnerabilities being resolved this month. The good news is most of them are in the OS including the Zero Day and three of four of the Publicly Disclosed vulnerabilities. Knocking the OS out quickly will reduce a significant amount of risk for your organization. Top priorities this month should include the Windows OS, Edge (Chromium), and Exchange Server.
  • 5. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. In the News
  • 6. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. In the News Source: Microsoft  Pwn2Own Results – What to expect in the next 90 days  https://www.zerodayinitiative.com/blog/2021/4/2/pwn2own- 2021-schedule-and-live-results  FBI blasts away web shells on US servers in wake of Exchange vulnerabilities  https://www.zdnet.com/article/fbi-blasts-away-web-shells-on-us- servers-in-wake-of-exchange-vulnerabilities/?&web_view=true  RemoteFX vGPU removed from all applicable Windows platforms this month  https://support.microsoft.com/en-us/topic/kb4570006-update- to-disable-and-remove-the-remotefx-vgpu-component-in- windows-bbdf1531-7188-2bf4-0de6-641de79f09d2
  • 7. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. Publicly Disclosed Vulnerabilities  CVE-2021-27091 RPC Endpoint Mapper Service Elevation of Privilege Vulnerability  https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-27091  CVE-2021-28312 Windows NTFS Denial of Service Vulnerability  https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-28312  CVE-2021-28437 Windows Installer Information Disclosure Vulnerability  https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-28437  CVE-2021-28458 Azure ms-rest-nodeauth Library Elevation of Privilege Vulnerability  https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-28458 Source: Microsoft
  • 8. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. Known Exploited Vulnerability  CVE-2021-28310 Win32k Elevation of Privilege Vulnerability  https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-28310 Source: Microsoft Affected Products: Windows 10 1803 – 20H2 Windows Server, 1909 - 2004 Severity: Critical Base CVSS 3.0 Score: 7.8
  • 9. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. Microsoft Patch Tuesday Updates of Interest  Advisory 990001 Latest Servicing Stack Updates (SSU)  https://msrc.microsoft.com/update-guide/en-US/vulnerability/ADV990001  Updated SSUs this month  See Table  Development Tool and Other Updates  Azure DevOps Server 2019-2020  Azure @azure/ms-rest-nodeauth  Azure Sphere  Team Foundation Server 2015-2018  Visual Studio 2015-2019  Visual Studio Code (multiple components) Source: Microsoft
  • 10. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. Windows 10 Lifecycle Awareness Windows 10 Enterprise and Education Version Release Date End of Support Date 20H2 10/20/2020 5/9/2023 2004 5/27/2020 12/14/2021 1909 11/12/2019 5/10/2022 1903 5/21/2019 12/8/2020 1809 11/13/2018 5/11/2021 1803 4/30/2018 5/11/2021 1709 10/17/2017 10/13/2020 Windows Datacenter and Standard Server Version Release Date End of Support Date 20H2 10/20/2020 5/10/2022 2004 5/27/2020 12/14/2021 1909 11/12/2019 5/11/2021 1903 5/21/2019 12/8/2020  Lifecycle Fact Sheet  https://docs.microsoft.com/en-us/lifecycle/faq/windows  https://docs.microsoft.com/en-us/lifecycle/products/windows-server  https://docs.microsoft.com/en-us/lifecycle/products/windows-10-enterprise- and-education
  • 11. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. Patch Content Announcements  Announcements Posted on Community Forum Pages  https://forums.ivanti.com/s/group/CollaborationGroup/00Ba0000009oKICEA2  Subscribe to receive email for the desired product(s)
  • 12. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. Bulletins and Releases
  • 13. Copyright © 2021 Ivanti. All rights reserved. MS21-04-W10: Windows 10 Update  Maximum Severity: Critical  Affected Products: Microsoft Windows 10 Versions 1607, 1709, 1803, 1809, 1903, 1909, 2004, 20H2, Server 2016, Server 2019, Server version 1909, Server version 2004, Server version 20H2, IE 11, Legacy Edge and Edge Chromium  Description: This bulletin references 6 KB articles. See KBs for the list of changes.  Impact: Remote Code Execution, Security Feature Bypass, Spoofing, Denial of Service, Elevation of Privilege and Information Disclosure  Fixes 79 Vulnerabilities: CVE-2021-28312 and CVE-2021-28437 are publicly disclosed. CVE-2021-28310 is known exploited. See the Security Update Guide for the complete list of CVEs.  Restart Required: Requires restart  Known Issues: See next slides
  • 14. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. April Known Issues for Windows 10  KB 5001347 – Windows 10, Version 1607 and Server 2016  [Min Password] After installing KB4467684, the cluster service may fail to start with the error “2245 (NERR_PasswordTooShort)” if the group policy “Minimum Password Length” is configured with greater than 14 characters. Workaround: Set the domain default "Minimum Password Length" policy to less than or equal to 14 characters. Microsoft is working on a resolution.  KB 5001342 – Windows 10, Version 1809, Server 2019  [Asian Packs] After installing KB 4493509, devices with some Asian language packs installed may receive the error, "0x800f0982 - PSFX_E_MATCHING_COMPONENT_NOT_FOUND.“ Workaround: Uninstall and reinstall any recently added language packs or select Check for Updates and install the April 2019 Cumulative Update. See KB for more recovery details. Microsoft is working on a resolution.
  • 15. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. April Known Issues for Windows 10 (cont)  KB 5001337 – Windows 10 version 1909, Windows Server version 1909  [Outdated Updates] System and user certificates might be lost when updating a device from Windows 10, version 1809 or later to a later version of Windows 10. This primarily happens when managed devices are updated using outdated bundles or media through an update management tool such as Windows Server Update Services (WSUS) or Microsoft Endpoint Configuration Manager. Note: Devices using Windows Update for Business or that connect directly to Windows Update are not impacted. Workaround: If you have already encountered this issue on your device, you can mitigate it within the uninstall window by going back to your previous version of Windows. The uninstall window might be 10 or 30 days depending on the configuration of your environment and the version you’re updating to. See directions here. Microsoft is working on a resolution.
  • 16. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. April Known Issues for Windows 10 (cont)  KB 5001330 – Windows 10 version 2004, Windows Server version 2004, Windows 10 version 20H2, Windows Server version 20H2  [Editor] When using the Microsoft Japanese Input Method Editor (IME) to enter Kanji characters in an app that automatically allows the input of Furigana characters, you might not get the correct Furigana characters. You might need to enter the Furigana characters manually. Workaround: Microsoft is working on a resolution.  [Outdated Updates]
  • 17. Copyright © 2021 Ivanti. All rights reserved. MS21-04-MR2K8-ESU: Monthly Rollup for Windows Server 2008  Maximum Severity: Critical  Affected Products: Microsoft Windows Server 2008 and IE 9  Description: This security update includes improvements and fixes that were a part of update KB 5000844 (released March 9, 2021). Bulletin is based on KB 5001389. Security updates to Windows Apps, Windows Hybrid Cloud Networking, Windows Kernel, and Windows Media.  Impact: Remote Code Execution, Spoofing, Denial of Service, Elevation of Privilege and Information Disclosure  Fixes 47 Vulnerabilities: CVE-2021-28437 is publicly disclosed. See the Security Update Guide for the complete list of CVEs.  Restart Required: Requires restart  Known Issues: [File Rename] See next slide.
  • 18. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. April Known Issues for Server 2008  KB 5001389 – Windows Server 2008 (Monthly Rollup)  [File Rename] Certain operations, such as rename, that you perform on files or folders that are on a Cluster Shared Volume (CSV) may fail with the error, “STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)”. This occurs when you perform the operation on a CSV owner node from a process that doesn’t have administrator privilege. Workaround: Perform the operation from a process that has administrator privilege or perform the operation from a node that doesn’t have CSV ownership. Microsoft is working on a resolution.  KB 5001332 – Windows Server 2008 (Security-only Update)  [File Rename]
  • 19. Copyright © 2021 Ivanti. All rights reserved. MS21-04-SO2K8-ESU: Security-only Update for Windows Server 2008  Maximum Severity: Critical  Affected Products: Microsoft Windows Server 2008  Description: Bulletin is based on KB 5001332. Security updates to Windows Apps, Windows Hybrid Cloud Networking, Windows Kernel, and Windows Media.  Impact: Remote Code Execution, Spoofing, Denial of Service, Elevation of Privilege and Information Disclosure  Fixes 47 Vulnerabilities: CVE-2021-28437 is publicly disclosed. No CVEs are known exploited. See the Security Update Guide for the complete list of CVEs.  Restart Required: Requires restart  Known Issues: [File Rename] See previous slide.
  • 20. Copyright © 2021 Ivanti. All rights reserved. MS21-04-MR7-ESU: Monthly Rollup for Win 7 MS21-04-MR2K8R2-ESU Monthly Rollup for Server 2008 R2  Maximum Severity: Critical  Affected Products: Microsoft Windows 7, Server 2008 R2, and IE  Description: This security update includes improvements and fixes that were a part of update KB 5000841 (released March 9, 2021). Bulletin is based on KB 5001335. RemoteFX vGPU feature removed from codebase. Security updates to Windows Apps, Windows Hybrid Cloud Networking, Windows Kernel, and Windows Media.  Impact: Remote Code Execution, Security Feature Bypass, Spoofing, Denial of Service, Elevation of Privilege and Information Disclosure  Fixes 50 Vulnerabilities: CVE-2021-27091 and CVE-2020-28437 are publicly disclosed. See the Security Update Guide for the complete list of CVEs.  Restart Required: Requires restart  Known Issues: [File Rename]
  • 21. Copyright © 2021 Ivanti. All rights reserved. MS21-04-SO7-ESU: Security-only Update for Win 7 MS21-04-SO2K8R2-ESU: Security-only Update for Server 2008 R2  Maximum Severity: Critical  Affected Products: Microsoft Windows 7 and Server 2008 R2  Description: Bulletin is based on KB 5001392. Security updates to Windows Apps, Windows Hybrid Cloud Networking, and Windows Media.  Impact: Remote Code Execution, Security Feature Bypass, Spoofing, Denial of Service, Elevation of Privilege and Information Disclosure  Fixes 50 Vulnerabilities: CVE-2021-27091 and CVE-2020-28437 are publicly disclosed. See the Security Update Guide for the complete list of CVEs.  Restart Required: Requires restart  Known Issues: [File Rename]
  • 22. Copyright © 2021 Ivanti. All rights reserved. MS21-04-MR8: Monthly Rollup for Server 2012  Maximum Severity: Critical  Affected Products: Microsoft Windows Server 2012 and IE  Description: This security update includes improvements and fixes that were a part of update KB 5000847 (released March 9, 2021). Bulletin is based on KB 5001387. RemoteFX vGPU feature removed from codebase. Security updates to Windows Apps, Windows Input and Composition, Windows Hybrid Cloud Networking, Windows Kernel, and Windows Media.  Impact: Remote Code Execution, Security Feature Bypass, Spoofing, Denial of Service, Elevation of Privilege and Information Disclosure  Fixes 54 Vulnerabilities: CVE-2021-27091 and CVE-2020-28437 are publicly disclosed. See the Security Update Guide for the complete list of CVEs.  Restart Required: Requires restart  Known Issues: [File Rename]
  • 23. Copyright © 2021 Ivanti. All rights reserved. MS21-04-SO8: Security-only Update for Windows Server 2012  Maximum Severity: Critical  Affected Products: Microsoft Windows Server 2012  Description: Bulletin is based on KB 5001383. Security updates to Windows Apps, Windows Input and Composition, Windows Hybrid Cloud Networkin2, Windows Kernel, and Windows Media.  Impact: Remote Code Execution, Security Feature Bypass, Spoofing, Denial of Service, Elevation of Privilege and Information Disclosure  Fixes 54 Vulnerabilities: CVE-2021-27091 and CVE-2020-28437 are publicly disclosed. See the Security Update Guide for the complete list of CVEs.  Restart Required: Requires restart  Known Issues: [File Rename]
  • 24. Copyright © 2021 Ivanti. All rights reserved. MS21-04-MR81: Monthly Rollup for Win 8.1 and Server 2012 R2  Maximum Severity: Critical  Affected Products: Microsoft Windows 8.1, Server 2012 R2, and IE  Description: This security update includes improvements and fixes that were a part of update KB 5000848 (released March 9, 2021). Bulletin is based on KB 5001382. RemoteFX vGPU feature removed from codebase. Security updates to Windows Input and Composition, Windows Fundamentals, Windows Hybrid Cloud Networking, Windows Kernel, and Windows Media.  Impact: Remote Code Execution, Security Feature Bypass, Spoofing, Denial of Service, Elevation of Privilege and Information Disclosure  Fixes 55 Vulnerabilities: CVE-2020-28437 is publicly disclosed. See the Security Update Guide for the complete list of CVEs.  Restart Required: Requires restart  Known Issues: [File Rename]
  • 25. Copyright © 2021 Ivanti. All rights reserved. MS21-04-SO81: Security-only Update for Win 8.1 and Server 2012 R2  Maximum Severity: Critical  Affected Products: Microsoft Windows 8.1, Server 2012 R2  Description: Bulletin is based on KB 5001393. Security updates to Windows Input and Composition, Windows Fundamentals, Windows Hybrid Cloud Networking, Windows Kernel, and Windows Media.  Impact: Remote Code Execution, Security Feature Bypass, Spoofing, Denial of Service, Elevation of Privilege and Information Disclosure  Fixes 55 Vulnerabilities: CVE-2020-28437 is publicly disclosed. See the Security Update Guide for the complete list of CVEs.  Restart Required: Requires restart  Known Issues: [File Rename]
  • 26. Copyright © 2020 Ivanti. All rights reserved. MS21-04-EXCH: Security Updates for Exchange Server  Maximum Severity: Critical  Affected Products: Microsoft Exchange Server 2013 - 2019  Description: This security update fixes vulnerabilities in Microsoft Exchange. This bulletin is based on KB 5001779.  Impact: Remote Code Execution  Fixes 4 Vulnerabilities: No CVEs are publicly disclosed or known exploited. CVE-2021-28480, CVE-2021-28481, CVE-2021-28482, and CVE-2021-28483 are fixed in this release.  Restart Required: Requires restart  Known Issues: Must install update with administrator privileges
  • 27. Copyright © 2021 Ivanti. All rights reserved. MS21-04-OFF: Security Updates for Microsoft Office  Maximum Severity: Important  Affected Products: Excel 2010-2016, Office 2010-2016, Office 2019 for macOS, Office Online Server, Office Web Apps 2010 and 2013, Outlook 2010-2016, Word 2010-2016.  Description: This security update resolves multiple vulnerabilities in Microsoft Office applications. Consult the Security Update Guide for specific details on each. This bulletin references 23 KB articles plus release notes for the macOS Office.  Impact: Remote Code Execution and Information Disclosure  Fixes 6 Vulnerabilities: No vulnerabilities are publicly disclosed or known exploited. CVE-2021-28449, CVE-2021-28451, CVE-2021-28452, CVE-2021-28453, CVE-2021-28454, and CVE-2021-28456 are fixed in this release.  Restart Required: Requires application restart  Known Issues: None reported
  • 28. Copyright © 2021 Ivanti. All rights reserved. MS21-04-O365: Security Updates Microsoft 365 Apps and Office 2019  Maximum Severity: Important  Affected Products: Microsoft 365 Apps, Office 2019  Description: This month’s update resolved various bugs and performance issues in Microsoft 365 Apps and Office 2019 applications. Information on Microsoft 365 Apps security updates is available at https://docs.microsoft.com/en- us/officeupdates/microsoft365-apps-security-updates.  Impact: Remote Code Execution and Information Disclosure  Fixes 6 Vulnerabilities: No vulnerabilities are publicly disclosed or known exploited. CVE-2021-28449, CVE-2021-28451, CVE-2021-28452, CVE-2021-28453, CVE-2021-28454, and CVE-2021-28456 are fixed in this release.  Restart Required: Requires application restart  Known Issues: None reported
  • 29. Copyright © 2021 Ivanti. All rights reserved. MS21-04-SPT: Security Updates for SharePoint Server  Maximum Severity: Important  Affected Products: Microsoft SharePoint Server 2010, Microsoft SharePoint Foundation Server 2013, Microsoft SharePoint Enterprise Server 2016, and Microsoft SharePoint Server 2019  Description: This security update resolves vulnerabilities in Microsoft Office that could allow remote code execution if a user opens a specially crafted Office file. This bulletin is based on 8 KB articles.  Impact: Remote Code Execution and Denial of Service  Fixes 2 Vulnerabilities: No CVEs are publicly disclosed or known exploited. CVE- 2021-28450 and CVE-2021-28453 are fixed in this release.  Restart Required: Requires restart  Known Issues: None reported
  • 30. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. Between Patch Tuesdays
  • 31. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. Release Summary  Security Updates: Google Chrome (2), Firefox (1), Firefox ESR (1), Cisco Jabber (1), Node.JS (4), SeaMonkey (1), Thunderbird (2), VMware Horizon Client (1), Wireshark (2)  Non-Security Updates: AIMP (1), Allway Sync (1), Adobe Acrobat and Reader (1), Audacity (1), Bandicut (2), Box Edit (1), CCleaner (1), ClickShare (1), Falcon sensor for Window (2), Citrix Workspace App (2), CutePDF Writer (1), DropBox (2), Evernote (2), Firefox (1), Foxit Reader (1), FileZilla Client (2), Foxit PhantomPDF (1), GoodSync (8), GIMP (1), GIT for windows (2), Google Backup and Sync (1), Cisco Jabber (1), BlueJeans (1), LibreOffice (2), LogMeIn (1), Malwarebytes (1), Nitro Pro (2), Node.JS (3), Notepad (2), Opera (5), Pidgin (2), Plex Media Server (4), PSPad (1), PeaZip (1), R for Windows (1), RingCentral App (1), RedHat OpenJDK (3), Royal TS (2), RealVNC Server (1), Slack Machine-Wide Installer (1), Snagit (1), Splunk Universal Forwarder (1), Sourcetree (1), Tableau Desktop (9), Tableau Reader (2), TortoiseGit (1), TortoiseHG (1), Apache Tomcat (4), TeamViewer (7), VMware Horizon Client (2), VMware Workstation (1), Cisco WebEx Teams (2), Zoom Client (2), Zoom Outlook Plugin (2)
  • 32. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. Third Party CVE Information (cont)  Cisco Jabber 12.9.5.305511  JABBER-210201, QJABBER1295305511  Fixes 5 Vulnerabilities: CVE-2021-1411, CVE-2021-1417, CVE-2021-1418, CVE- 2021-1469, CVE-2021-1471  Google Chrome 89.0.4389.90  CHROME-210312, QGC890438990  Fixes 3 Vulnerabilities: CVE-2021-21191, CVE-2021-21192, CVE-2021-21193  Google Chrome 89.0.4389.114  CHROME-2103312, QGC8904389114  Fixes 6 Vulnerabilities: CVE-2021-21194, CVE-2021-21195, CVE-2021-21196, CVE-2021-21197, CVE-2021-21198, CVE-2021-21199
  • 33. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. Third Party CVE Information  Firefox 87.0  FF-210323, QFF870  Fixes 8 Vulnerabilities: CVE-2021-23981, CVE-2021-23982, CVE-2021-23983, CVE-2021-23984, CVE-2021-23985, CVE-2021-23986, CVE-2021-23987, CVE- 2021-23988  Firefox ESR 78.9.0  FFE-210323, QFFE7890  Fixes 4 Vulnerabilities: CVE-2021-23981, CVE-2021-23982, CVE-2021-23984, CVE-2021-23987  VMware Horizon Client 5.5.1  VMWH5-210323, QVMWH551  Fixes 1 Vulnerability: CVE-2020-3991
  • 34. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. Third Party CVE Information  Node.JS 15.14.0 (Current)  NOJSC-210406, QNODEJSC15140  Fixes 3 Vulnerabilities: CVE-2021-3449, CVE-2021-3450, CVE-2021-7774  Node.JS 12.22.1 (LTS Lower)  NOJSLL-210406, QNODEJSLL12221  Fixes 3 Vulnerabilities: CVE-2021-3449, CVE-2021-3450, CVE-2021-7774  Node.JS 14.16.1 (LTS Upper)  NOJSLU-210406, QNODEJSLU14161  Fixes 3 Vulnerabilities: CVE-2021-3449, CVE-2021-3450, CVE-2021-7774  Node.JS 10.24.1 (Maintain)  NOJSM-210406, QNODEJSLL10241  Fixes 3 Vulnerabilities: CVE-2021-3449, CVE-2021-3450, CVE-2021-7774
  • 35. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. Third Party CVE Information (cont)  SeaMonkey 2.53.7  SM20-210330, QSM2537  Fixes 14 Vulnerabilities: CVE-2018-12359, CVE-2018-12360, CVE-2018-12361, CVE-2018-12362, CVE-2018-12363, CVE-2018-12364, CVE-2018-12365, CVE- 2018-12366, CVE-2018-12367, CVE-2018-12368, CVE-2018-12371, CVE-2018- 5156, CVE-2018-5187, CVE-2018-5188  Thunderbird 78.9.0  TB-210325, QTB7890  Fixes 4 Vulnerabilities: CVE-2021-23981, CVE-2021-23982, CVE-2021-23984, CVE-2021-23987
  • 36. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. Third Party CVE Information (cont)  Thunderbird 78.9.1  TB-210409, QTB7891  Fixes 2 Vulnerabilities: CVE-2021-23991, CVE-2021-23993  Wireshark 3.2.12  WIRES32-210311, QWIRES3212  Fixes 1 Vulnerability: CVE-2021-22191  Wireshark 3.4.4  WIRES32-210311, QWIRES344  Fixes 1 Vulnerability: CVE-2021-22191
  • 37. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. Q & A
  • 38. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. Prochain Rendez-Vous Patch Tuesday  Mardi 18 mai – 16h00  Jeudi 10 juin – 16h00  Mardi 20 juillet – 16h00  Jeudi 12 août – 16h00  Jeudi 16 septembre – 16h00 https://www.ivanti.fr/resources/patch-tuesday
  • 39. Copyright © 2021 Ivanti. All rights reserved. Copyright © 2021 Ivanti. All rights reserved. Thank You!