SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Microsoft December 2021 Patch Tuesday Addresses 67 Vulnerabilities Including a Zero-Day Being Actively Exploited

Microsoft December 2021 Patch Tuesday Addresses 67 Vulnerabilities Including a Zero-Day Being Actively Exploited

Microsoft has released December 2021 Patch Tuesday security updates with a total of 67 Vulnerabilities, including a zero-day being actively exploited. Detected by a vulnerability scanning tool,  The products covered in December’s security update include Microsoft Edge, Azure, Microsoft Windows, Micr...

Dec 14, 2021By Pranav S4 min read

Microsoft has released December 2021 Patch Tuesdaysecurity updates with a total of 67 Vulnerabilities, including a zero-day being actively exploited. Detected by a vulnerability scanning tool,  The products covered in December’s security update include Microsoft Edge, Azure, Microsoft Windows, Microsoft Office, Microsoft Excel, the Chromium-based Edge browser, Visual Studio Code, Windows Kernel, Print Spooler, Remote Desktop Client, etc.

The vulnerability for Windows AppX Installer (CVE-2021-43890) has been actively exploited. Auto patching can patch this CVE.

Zero-day Vulnerabilities

CVE-2021-43890 – Windows AppX Installer Spoofing Vulnerability. This vulnerability allows an attacker to create a malicious package file and then modify it to look like a legitimate application and has been used to deliver Emotet malware, which made a comeback this year. This flaw requires the attacker to convince a user to open a malicious attachment, which would be conducted through a phishing attack.

CVE-2021-41333 – Windows Print Spooler Elevation of Privilege Vulnerability. Also, It was issued a CVSS score of 7.8. The vulnerability has a low attack complexity.

CVE-2021-43880 — Windows Mobile Device Management Elevation of Privilege Vulnerability. Also, This vulnerability allows local attackers to delete targeted files on a system.

CVE-2021-43883 — Windows Installer Elevation of Privilege Vulnerability. Also, This vulnerability allows unauthorized privilege escalation.

CVE-2021-43893 — Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability.

Critical Vulnerabilities

Here are some critical vulnerabilities fixed by Patch Tuesday December 2021

CVE-2021-43215 — iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution. The vulnerability targets the Internet Storage Name Service (iSNS) protocol. An attacker could send a specially crafted request to the Internet Storage Name Service (iSNS) server and then resulting in remote code execution.

CVE-2021-43217 — Windows Encrypting File System (EFS) Remote Code Execution Vulnerability. Also This vulnerability targets Encrypting File System (EFS), where an attacker could cause a buffer overflow to write, leading to unauthenticated non-sandboxed code execution.

CVE-2021-43905 — Microsoft Office app Remote Code Execution Vulnerability. Also, This is an unauthenticated Remote Code Execution vulnerability in the Microsoft Office app.

CVE-2021-43233 — Remote Desktop Client Remote Code Execution Vulnerability. Also, This is a critical Remote Code Execution vulnerability included in the monthly rollup for Windows.

Microsoft security bulletin summary for December 2021

  1.  Windows Media
  2.  Microsoft Windows Codecs Library
  3.  Microsoft Defender for IoT
  4.  Internet Storage Name Service
  5. Microsoft Local Security Authority Server (lsasrv)
  6. Windows Encrypting File System (EFS)
  7. Windows DirectX
  8. Microsoft Message Queuing
  9. Windows Remote Access Connection Manager
  10. Windows Common Log File System Driver
  11. Azure Bot Framework SDK
  12. Windows Storage Spaces Controller
  13. Windows SymCrypt
  14. Windows NTFS
  15. Windows Event Tracing
  16.  Remote Desktop Client
  17. Role: Windows Fax Service
  18. Windows Storage
  19. Windows Update Stack
  20. Windows Kernel
  21. Windows Digital TV Tuner
  22. Role: Windows Hyper-V
  23. Windows TCP/IP
  24. Office Developer Platform
  25. Microsoft Office
  26. ASP.NET Core & Visual Studio
  27. Visual Studio Code
  28. Microsoft Devices
  29. Windows Print Spooler Components
  30. Windows Mobile Device Management
  31. Windows Installer
  32. Microsoft PowerShell

Products Affected

2. Product: Microsoft OfficeCVEs/Advisory: CVE-2021-42293, CVE-2021-42295, CVE-2021-43255, CVE-2021-43256, CVE-2021-43875Impact: Spoofing, Elevation of Privilege, Remote Code ExecutionKBs: 4486726, 4504710, 4504745, 5002033, 5002099, 5002101, 5002103, 5002104

4. Product: Microsoft ExcelCVEs/Advisory: CVE-2021-43256Impact: Remote Code ExecutionKBs: 4486726, 4504710, 4504745, 5002033, 5002099, 5002101, 5002103, 5002104

5. Product: Microsoft SharePointCVEs/Advisory: CVE-2021-42294, CVE-2021-42309, CVE-2021-42320 and then CVE-2021-43242Impact: Remote Code Execution, SpoofingKBs: 5002008, 5002015, 5002045, 5002047, 5002054, 5002055, 5002059, 5002061, 5002071

Also, SanerNow VM and SanerNow PM detect these vulnerabilities and automatically fix them by applying security updates. However, Use SanerNow and keep your systems updated and secure.

Featured Posts

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026
Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

CVE Research

Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

Three Linux kernel vulnerabilities entered CISA’s KEV catalog on September 18, 2026, although their Linux 6.12 fixes were available 91–386 days earlier. This analysis separates patch availability, CVE publication, and known-exploitation status without treating KEV dates as first-attack dates.

Sep 28, 2026