Microsoft Patch Tuesday April 2021 - Summary

Apr 13 2021

7

Bulletins

107

Patches

47

Updates

108

Vulnerabilities

6

Impacts

CVE Index for April 2021 Patch Tuesday Updates

CVE ID
Impact Component Type of update
CVE-2021-28460 Azure Sphere Unsigned Code Execution Security update
CVE-2021-28480 Microsoft Exchange Server Remote Code Execution Security update
CVE-2021-28481 Microsoft Exchange Server Remote Code Execution Security update
CVE-2021-28482 Microsoft Exchange Server Remote Code Execution Security update
CVE-2021-28483 Microsoft Exchange Server Remote Code Execution Security update
CVE-2021-28315 Windows Media Player Remote Code Execution Security update
CVE-2021-27095 Windows Media Player Remote Code Execution Security update
CVE-2021-28336 Windows Remote Procedure Call Runtime Remote Code Execution Security update
CVE-2021-28335 Windows Remote Procedure Call Runtime Remote Code Execution Security update
CVE-2021-28334 Windows Remote Procedure Call Runtime Remote Code Execution Security update
CVE-2021-28338 Windows Remote Procedure Call Runtime Remote Code Execution Security update
CVE-2021-28337 Windows Remote Procedure Call Runtime Remote Code Execution Security update
CVE-2021-28333 Windows Remote Procedure Call Runtime Remote Code Execution Security update
CVE-2021-28329 Windows Remote Procedure Call Runtime Remote Code Execution Security update
CVE-2021-28330 Windows Remote Procedure Call Runtime Remote Code Execution Security update
CVE-2021-28332 Windows Remote Procedure Call Runtime Remote Code Execution Security update
CVE-2021-28331 Windows Remote Procedure Call Runtime Remote Code Execution Security update
CVE-2021-28339 Windows Remote Procedure Call Runtime Remote Code Execution Security update
Windows Win32K Zero-day vulnerability Elevation of Privilege CVE-2021-28310
RPC Endpoint Mapper Service Elevation of Privilege Vulnerability CVE-2021-27091
Windows NTFS Zero-day vulnerability Denial of Service Vulnerability CVE-2021-28312
Windows Installer Zero-day vulnerability Information Disclosure Vulnerability CVE-2021-28437
Azure ms-rest-node authorization Library Elevation of Privilege Vulnerability CVE-2021-28458

Previous Patch Tuesday Updates and Fixes

7 essential vulnerability management questions answered

Microsoft Windows Patch Tuesday - Overview

What is Patch Tuesday?

Patch Tuesday, the colloquial term for Microsoft's Update Tuesday that falls on second Tuesday of every month. That is when Microsoft rolls out patch updates to improve security of Microsoft applications. Coinciding with the Patch Tuesday it is also a general trend for the roll out of patch updates for other third party applications that include Adobe and Mozilla, among many others.

When is Patch Tuesday?

The upcoming Patch Tuesday falls on May 11, 2021.

What is patching and why is it important?

Patches are nothing but pieces of software code that are written to fix a bug in a software application, that might lead to a vulnerability. Such vulnerabilities in any application are loop holes for attackers to get their hands on business critical data and information. So it is highly crucial to keep all the applications in a network updated to its latest versions. Updating applications in mobile phones and laptops also work in the same manner by preventing theft of personal data, through security flaws.

What kind of patch updates are released during Patch Tuesday?

Predominantly security patch updates of varying severity like Critical, Important, Moderate & Low are labeled and released. It is always a best practice to prioritize your patching based on the severity level mentioned.

What are CVE IDs?

CVE ID - Common Vulnerabilities and Exposure ID is a format in which each vulnerability is disclosed and cataloged in the National Vulnerability Database (NVD). You can look up for a detailed explanation of each vulnerability in the NVD with the help of CVE ID. In Patch Manager Plus you can make use of these CVE IDs to fetch the appropriate patches to deploy. You can find the CVE IDs here.

How to register for ManageEngine's Free Patch Tuesday webinar?

The upcoming Free Patch Tuesday webinar by ManageEngine is scheduled on -. You can make your registrations here

Where can I find more details about individual bulletins?

Each CVE ID listed in the CVE Index section has been linked to its security advisory.