# Microsoft Patches Two Exploited Zero-Days

Published: 2021-11-09 · Severity: high
Canonical: https://vorant.io/reports/ab8f1dc7-4070-53ac-b451-0e05dd7c5500/microsoft-patches-two-exploited-zero-days

> Microsoft's November 2021 update fixes actively exploited flaws CVE-2021-42292 and CVE-2021-42321; IPA urges urgent patching.

Japan's IPA issued an alert on November 10, 2021 regarding Microsoft's monthly security update, which addresses multiple vulnerabilities across Microsoft products. Among these, Microsoft confirmed that CVE-2021-42292 and CVE-2021-42321 are being actively exploited in the wild, prompting IPA to urge immediate patch application to prevent further damage.

Exploitation of the disclosed vulnerabilities could allow attackers to crash applications or take control of affected systems, leading to a range of potential impacts. The advisory is a standard notification directing users to apply Microsoft's patches via Windows Update, with no further technical detail on exploitation methods, affected sectors, or threat actors provided in the source.

## Mentioned in this report

- Vulnerabilities: CVE-2021-42292 (KEV), CVE-2021-42321 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2021/20211110-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ab8f1dc7-4070-53ac-b451-0e05dd7c5500/microsoft-patches-two-exploited-zero-days.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
