Microsoft Fixes Six Exploited Zero-Day Vulnerabilities in February Update
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Microsoft released an update on February’s Patch Tuesday to address six zero-day vulnerabilities that had been exploited prior to the patch. Among these vulnerabilities are the Windows Shell Security Feature Bypass (CVE-2026-21510) and the Internet Explorer Security Feature Bypass (CVE-2026-21513), both rated at 8.8 on the CVSS scale. These flaws allow attackers to execute code by convincing users to open malicious links or files.
Another vulnerability, the Microsoft Word Security Feature Bypass (CVE-2026-21514), rated at 7.8, also enables remote code execution through malicious Office files. Additionally, the Desktop Window Manager Elevation of Privilege Vulnerability (CVE-2026-21519) allows attackers to gain SYSTEM privileges, while the Windows Remote Access Connection Manager Denial of Service Vulnerability (CVE-2026-21525) can deny service locally. Lastly, the Windows Remote Desktop Services Elevation of Privilege Vulnerability (CVE-2026-21533) permits an attacker to run code with SYSTEM privileges.
Understanding the Risks
The presence of these vulnerabilities, especially those that are publicly disclosed, indicates a heightened risk for users and organizations. Attackers may exploit these flaws to gain unauthorized access or execute harmful code, potentially leading to data breaches or system compromises. The fact that three of the vulnerabilities are already known to be exploited in the wild underscores the urgency for users to apply the patches promptly.
Organizations should prioritize updating their systems to protect against these vulnerabilities. The reliance on user interaction to trigger these exploits, such as opening malicious links or files, highlights the need for ongoing user education about cybersecurity best practices. Users should be cautious about unsolicited emails or links, especially those that seem suspicious.
Given that Internet Explorer is no longer supported, the risk may be lower for those who have transitioned to modern browsers. However, organizations still using older software should assess their risk posture and consider migrating to supported platforms to avoid similar vulnerabilities in the future.
- Windows Shell Security Feature Bypass Vulnerability (CVE-2026-21510): This flaw allows attackers to bypass security prompts and execute code on user systems.
- Internet Explorer Security Feature Bypass Vulnerability (CVE-2026-21513): This vulnerability can lead to remote code execution if users open malicious files.
- Microsoft Word Security Feature Bypass Vulnerability (CVE-2026-21514): Attackers can exploit this flaw through malicious Office files to gain access to system controls.
- Desktop Window Manager Elevation of Privilege Vulnerability (CVE-2026-21519): This vulnerability allows attackers to gain SYSTEM privileges on affected systems.
- Windows Remote Access Connection Manager Denial of Service Vulnerability (CVE-2026-21525): This flaw enables unauthorized denial of service locally.
- Windows Remote Desktop Services Elevation of Privilege Vulnerability (CVE-2026-21533): This vulnerability allows attackers to run code with SYSTEM privileges due to improper privilege management.
Key Takeaways
- Update your Microsoft software immediately to patch the six vulnerabilities mentioned.
- Educate users on the risks of opening unsolicited links or files to prevent exploitation.
- Monitor your systems for unusual activity that may indicate an attempted exploit.
- Consider transitioning away from unsupported software like Internet Explorer to reduce risk.
- Review your organization’s cybersecurity policies to ensure they address these vulnerabilities effectively.
Key Terms & Concepts
- CVE: CVE refers to a Common Vulnerabilities and Exposures identifier used to catalog security vulnerabilities.
- CVSS: CVSS stands for Common Vulnerability Scoring System, which rates the severity of vulnerabilities.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.