Patchday March
Patchday March
It's that time again: The second Wednesday of the month is the day after the second Tuesday of the month and so it's time for our Patchday review. As always, we are focussing on the big three: Adobe, Microsoft and SAP. This month we are starting with information on Microsoft, as this is the most relevant. Especially if you have relevant Exchange servers in use.
Microsoft
The BSI had set the threat level to level 4/red on 05.03.2021. This was subsequently widely reported and the BSI provided guidance on how to deal with this issue. According to BSI circles:
"The IT threat situation is extremely critical. Many services are down, regular operations cannot be maintained."
The CERT-Bund, which is based at the BSI, suspects more than 26,000 vulnerable Exchange servers in Germany that can be accessed directly from the internet. In addition, there are at least as many servers for which it is not possible to say exactly whether they have already received the protective updates. There is therefore an urgent need for action!
In about half of the systems, it is not possible to determine whether they are still vulnerable. The CERT-Bund is currently informing affected companies.(Image: CERT-Bund)
The following vulnerabilities must therefore be closed with the highest priority:
CVE-2021-26855 is a server-side request forgery (SSRF) vulnerability in Exchange that allows an attacker to send HTTP requests and authenticate to the Exchange server
CVE-2021-26857 is an insecure deserialisation vulnerability in the Unified Messaging Service. With insecure deserialisation, user-defined data is deserialised by a program. This makes it possible to execute arbitrary programme code as SYSTEM on the Exchange server. This requires administrator rights or the exploitation of a corresponding additional vulnerability.
CVE-2021-26858 and CVE-2021-27065 are vulnerabilities with which - after authentication - arbitrary files can be written to the Exchange server. Authentication can take place via CVE-2021-26855 or leaked administrator credentials, for example.
Recommended action
If you have relevant Exchange servers in use, please check the following questions immediately for each server in use:
Has the server already been compromised?
Has the server been equipped with the latest updates?
If you need help with this, please feel free to contact us (contact). It is very important that this check is carried out comprehensively in order to prevent further compromise. If you have not yet installed the latest patches, please do so immediately.
For the whole of March, Microsoft released patches for 89 individual CVEs covering Microsoft Windows components, Azure and Azure DevOps, Azure Sphere, Internet Explorer and Edge (EdgeHTML), Exchange Server, Office and Office Services and Web Apps, SharePoint Server, Visual Studio and Windows Hyper-V. These 89 CVEs include the seven Exchange CVEs that were released last week (mentioned above). Of these 89 bugs, 14 are categorised as critical and 75 as important.
Let's take a closer look at some of the more interesting updates for this month, starting with the other bug listed as an active attack:
CVE-2021-26411 - Memory corruption vulnerability in Internet Explorer. This patch fixes a flaw in Internet Explorer (IE) and Edge (EdgeHTML-based) that could allow an attacker to execute their code on affected systems when they display a specially crafted HTML file.
CVE-2021-26897 - Windows DNS server vulnerability with remote code execution. Testing and installing these updates should be prioritised.
CVE-2021-26867 - Remote code execution vulnerability in Windows Hyper-V. This flaw could allow an authenticated attacker to execute code on the underlying Hyper-V server. Although the vulnerability is listed with a CVSS score of 9.9, it is actually only relevant for those using the Plan 9 file system.
CVE-2021-27076 - Microsoft SharePoint Server remote code execution vulnerability. This patch fixes a code execution bug that was originally submitted via the ZDI programme. For an attack to be successful, the attacker must be able to create or modify sites using the SharePoint server. However, the default configuration of SharePoint allows authenticated users to create sites. If they do so, the user is the owner of that site and has all the necessary permissions.
Adobe
In March, Adobe three patches for eight CVEs in Adobe Connect, Creative Cloud Desktop and Framemaker. Two of these CVEs were deployed via the ZDI programme. The update for Framemaker fixes a single out-of-bounds (OOB) read vulnerability that could lead to remote code execution. The update for Creative Cloud fixes three different CVEs categorised as critical. Two of these flaws could lead to code execution, while the third could allow privilege escalation. The latest Adobe patch for March covers one critical and three important vulnerabilities in Adobe Connect. The flaw categorised as critical could lead to the execution of arbitrary code, while the other fixed flaws are reflective cross-site scripting (XSS) flaws). None of the vulnerabilities fixed by Adobe are publicly known or under active attack at the time of publication. Overview of critical CVEs:
Adobe Connect:
CVE-2021-21085 - Improper Input Validation / Arbitrary code execution
Adobe Creative Cloud Desktop Application:
CVE-2021-21068 - Arbitrary file overwrite / Arbitrary code execution
CVE-2021-21078 - OS Command Injection / Arbitrary Code Execution
CVE-2021-21069 - Improper Input Validation / Privilege escalation
Adobe Framemaker:
CVE-2021-21056 - Out-of-Bounds Read / Arbitrary code execution
SAP
SAP has made reference to 18 vulnerabilities in the March update. The Security Report contains four HotNews advisories and one with High Priority. Let's take a closer look at these.
CVE-2020-6207 - Missing Authentication Check in SAP Solution Manager (User-Experience Monitoring) was rated 10.0 as well as
CVE-2021-21148 - Security updates for the browser control Google Chromium delivered with SAP Business Client.
Both HotNews items refer to already fixed update patches from November 2020 and April 2018, which have been continued here. The situation is different for
CVE-2021-21480 - Code Injection Vulnerability in SAP MII SAP Security Note #3022622, labelled with a CVSS score of 9.9, fixes a very critical code injection vulnerability in SAP Manufacturing Intelligence and Integrations (SAP MII). SAP MII or xMII (the former name) is a platform based on SAP NetWeaver AS Java that enables real-time production monitoring and provides extensive data analysis tools. It acts as a data hub between SAP ERP and operational applications such as Manufacturing Execution Systems (MES). An integral part of SAP MII is the Self-Service Composition Environment (SSCE), with which dashboards can be designed by simple drag-and-drop. The SSCE allows users to save a dashboard as a JSP file. An attacker can intercept a request to the server, inject malicious JSP code into the request and forward it to the server. If such an infected dashboard is opened in production by a user who has minimum privileges, the malicious content will be executed, resulting in remote code execution on the server. Some possible actions are:
accessing the SAP databases and reading/modifying/deleting arbitrary records in arbitrary tables
using these servers to pivot to other servers
placing malware, to later infect end users
Change network configurations and potentially compromise internal networks The patch prevents dashboards from being saved as JSP files. Unfortunately, there is no more flexible solution. If JSP files are required, customers should restrict access to the SSCE as much as possible and manually validate all JSP content before it goes into production.
These are once again some to-dos for the IT department or service provider. We can only emphasise again and again that well-functioning patch management is essential for securing the infrastructure. If you need support with this, please do not hesitate to contact us. If you do not have any resources available internally for such issues - use our services and we will take care of it for you.
Stay safe & healthy. Until next month, when it's patchday again!
Resources:

Michael Döhmen
Chief Marketing Officer
Published on 14.05.2025
