- Aug 17, 2014
- 11,547
Today is Microsoft's April 2021 Patch Tuesday, and with it comes five zero-day vulnerabilities and more Critical Microsoft Exchange vulnerabilities. It has been a tough couple of months for Windows and Microsoft Exchange admins, and it looks like April won't be any easier, so please be nice to your IT staff today.
With today's update, Microsoft has fixed 108 vulnerabilities, with 19 classified as Critical and 89 as Important. These numbers do not include the 6 Chromium Edge vulnerabilities released earlier this month.
There are also five zero-day vulnerabilities patched today that were publicly disclosed, with one known to be used in attacks.
To make matters worse, Microsoft fixed four critical Microsoft Exchange vulnerabilities that the NSA discovered.
Five zero-day vulnerabilities fixed
As part of today's Patch Tuesday, Microsoft has fixed four publicly disclosed vulnerabilities and one actively exploited vulnerability.
The following four vulnerabilities Microsoft states were publicly exposed but not exploited:
The following vulnerability discovered by Kaspersky researcher Boris Larin was found exploited in the wild.
- CVE-2021-27091 - RPC Endpoint Mapper Service Elevation of Privilege Vulnerability
- CVE-2021-28312 - Windows NTFS Denial of Service Vulnerability
- CVE-2021-28437 - Windows Installer Information Disclosure Vulnerability - PolarBear
- CVE-2021-28458 - Azure ms-rest-nodeauth Library Elevation of Privilege Vulnerability
- CVE-2021-28310 - Win32k Elevation of Privilege Vulnerability

Microsoft April 2021 Patch Tuesday fixes 108 flaws, 5 zero-days
Today is Microsoft's April 2021 Patch Tuesday, and with it comes five zero-day vulnerabilities and more Critical Microsoft Exchange vulnerabilities. It has been a tough couple of months for Windows and Microsoft Exchange admins, and it looks like April won't be any easier, so please be nice to...