[ad_1]
Microsoft on Tuesday rolled out its month-to-month safety updates with fixes for 51 vulnerabilities throughout its software program line-up consisting of Home windows, Workplace, Groups, Azure Knowledge Explorer, Visible Studio Code, and different elements equivalent to Kernel and Win32k.
Among the many 51 defects closed, 50 are rated Vital and one is rated Average in severity, making it one of many uncommon Patch Tuesday updates with none fixes for Crucial-rated vulnerabilities. That is additionally along with 19 extra flaws the corporate addressed in its Chromium-based Edge browser.
Not one of the safety vulnerabilities are listed as below lively exploit, whereas of the issues — CVE-2022-21989 (CVSS rating: 7.8) — has been categorized as a publicly disclosed zero-day on the time of the discharge. The difficulty issues a privilege escalation bug in Home windows Kernel, with Microsoft warning of potential assaults exploiting the shortcoming.
“Profitable exploitation of this vulnerability requires an attacker to take extra actions previous to exploitation to organize the goal atmosphere,” the corporate famous in its advisory. “A profitable assault may very well be carried out from a low privilege AppContainer. The attacker may elevate their privileges and execute code or entry assets at a better integrity degree than that of the AppContainer execution atmosphere.”
Additionally resolved are a lot of distant code execution vulnerabilities affecting Home windows DNS Server (CVE-2022-21984, CVSS rating: 8.8), SharePoint Server (CVE-2022-22005, CVSS rating: 8.8), Home windows Hyper-V (CVE-2022-21995, CVSS rating: 5.3), and HEVC Video Extensions (CVE-2022-21844, CVE-2022-21926, and CVE-2022-21927, CVSS scores: 7.8).
The safety replace additionally remediates a Azure Knowledge Explorer spoofing vulnerability (CVE-2022-23256, CVSS rating: 8.1), two safety bypass vulnerabilities every impacting Outlook for Mac (CVE-2022-23280, CVSS rating: 5.3) and OneDrive for Android (CVE-2022-23255, CVSS rating: 5.9), and two denial-of-service vulnerabilities in .NET (CVE-2022-21986, CVSS rating: 7.5) and Groups (CVE-2022-21965, CVSS rating: 7.5).
Microsoft additionally stated it remediated a number of elevation of privilege flaws — 4 within the Print Spooler service and one within the Win32k driver (CVE-2022-21996, CVSS rating: 7.8), the latter of which has been labeled “Exploitation Extra Seemingly” in gentle of the same vulnerability in the identical part that was patched final month (CVE-2022-21882) and has come since below lively assault.
The updates arrive because the tech big late final month republished a vulnerability relationship again to 2013 — a signature validation problem affecting WinVerifyTrust (CVE-2013-3900) — noting that the repair is “obtainable as an opt-in function by way of reg key setting, and is out there on supported editions of Home windows launched since December 10, 2013.”
The transfer might have been spurred in response to an ongoing ZLoader malware marketing campaign that, as uncovered by Examine Level Analysis in early January, was discovered leveraging the flaw to bypass the file signature verification mechanism and drop malware able to siphoning person credentials and different delicate info.
Software program Patches from Different Distributors
In addition to Microsoft, safety updates have additionally been launched by different distributors to rectify a number of vulnerabilities, counting —
[ad_2]
