July 2021 - Microsoft Releases Security Patches

  Advisory Date: JUL 14, 2021

  DESCRIPTION

In the November 2020 Microsoft security patch release, Microsoft updated its vulnerability information page. Following the new patch information format, below are the CVEs that Trend Micro Cloud One Workload covers in the July 2021 release:

  • CVE-2021-34527 - Windows Print Spooler Remote Code Execution Vulnerability
    CVSS:3.0 8.8/8.2

  • CVE-2021-34448 - Scripting Engine Memory Corruption Vulnerability
    CVSS:3.0 6.8/6.3

  TREND MICRO PROTECTION INFORMATION

Cloud One Workload and Deep Security shield networks through the following Deep Packet Inspection (DPI) rules. Trend Micro customers using the Vulnerability Protection are also protected from attacks using these vulnerabilities.

Vulnerability ID DPI Rule Number DPI Rule Name Release Date Vulnerability Protection Compatibility
CVE-2021-34527 1011016 Identified DCERPC AddPrinterDriverEx Call Over TCP Protocol (CVE-2021-34527) 13-Jul-21 YES
CVE-2021-34527 1011018 Identified DCERPC AddPrinterDriverEx Call Over SMB Protocol (CVE-2021-34527) 13-Jul-21 YES
CVE-2021-34448 1011040 Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability (CVE-2021-34448) 13-Jul-21 YES