Microsoft Patches Two Exploited Zero-Days
Microsoft's November 2021 update fixes actively exploited flaws CVE-2021-42292 and CVE-2021-42321; IPA urges urgent patching.
Japan's IPA issued an alert on November 10, 2021 regarding Microsoft's monthly security update, which addresses multiple vulnerabilities across Microsoft products. Among these, Microsoft confirmed that CVE-2021-42292 and CVE-2021-42321 are being actively exploited in the wild, prompting IPA to urge immediate patch application to prevent further damage.
Exploitation of the disclosed vulnerabilities could allow attackers to crash applications or take control of affected systems, leading to a range of potential impacts. The advisory is a standard notification directing users to apply Microsoft's patches via Windows Update, with no further technical detail on exploitation methods, affected sectors, or threat actors provided in the source.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2021/20211110-ms.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free