VORANT. Threat Intelligence Sign in Get the full feed

Microsoft released December 2021 security updates addressing multiple vulnerabilities…

high vulnerability

Microsoft released December 2021 security updates addressing multiple vulnerabilities, including CVE-2021-43890 confirmed as exploited in the wild.

On December 15, 2021, Microsoft published security updates addressing multiple vulnerabilities across its product portfolio. The Japan Information-technology Promotion Agency (IPA) issued an advisory urging immediate patching, particularly for CVE-2021-43890, which Microsoft confirmed is being actively exploited in the wild. Successful exploitation of these vulnerabilities could result in application crashes, arbitrary code execution, or complete system compromise by threat actors.

The advisory emphasizes the critical nature of CVE-2021-43890 due to confirmed exploitation and the risk of widespread impact. Organizations are urged to apply the security updates immediately through Windows Update mechanisms. The IPA provided guidance on patch deployment and directed users to contact product vendors for environment-specific implementation questions.

This represents a standard monthly security update cycle from Microsoft, elevated in urgency by the presence of an actively exploited vulnerability. The advisory follows typical vulnerability disclosure practices, with the Japanese government's IPA serving as the national CERT coordinating response efforts for Japanese organizations.

Mentioned in this report

Vulnerabilities CVE-2021-43890KEV

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2021/20211215-ms.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free