ALERT: Windows Update Patches Six Active Zero-Day Vulnerabilities
Microsoft's most recent monthly security updates included remedies for 68 vulnerabilities across its software portfolio, including patches for six actively exploited zero-day vulnerabilities.
Twelve of the issues are classified as Critical, two as High, and 55 as Important. This includes the vulnerabilities that OpenSSL fixed the previous week.
An actively exploited issue in Chromium-based browsers (CVE-2022-3723) was also addressed earlier this month.
"The important news is that two previous zero-day CVEs impacting Exchange Server, which were made public at the end of September, have now been addressed," Rapid7's Greg Wiseman explained in a statement shared with The Hacker News.
"Customers are encouraged to quickly update their Exchange Server systems, regardless of whether any previously recommended mitigating measures have been implemented. Once systems have been fixed, the mitigation rules are no longer advised."
The following is a list of actively exploited vulnerabilities that allow privilege elevation and remote code execution:
CVE-2022-41128 resides in the javascript library (JScript9) component and happens when a target is misled into visiting a specially designed website.
CVE-2022-41091 is one of two security bypass problems discovered in Windows Mark of the Web (MoTW) in recent months. It was recently uncovered that the Magniber ransomware attacker was using it to target consumers with bogus software upgrades.
According to a Microsoft advisory, "An attacker can develop a malicious file that will bypass Mark of the Web (MotW) safeguards, resulting in loss of integrity and availability of security features like Protected View in the Microsoft Office suite.
CVE-2022-41049 is the second MotW bug to be addressed (aka ZippyReads). It is related to a failure to set a Web flag Mark on extracted archive files, as Analygence security researcher Will Dormann reported.
The two privilege escalation weaknesses in Print Spooler and the CNG Key Isolation Service are exploited by threat actors due to an earlier compromise to gain SYSTEM rights, according to Kev Breen, Immersive Labs' director of cyber threat research.
Breen noted that this greater degree of access is required to disable security monitoring systems before conducting credential attacks with tools such as Mimikatz, which can allow hackers to move across a network.
领英推荐
Other critical issues in the November patch worth mentioning are privilege elevation flaws in Windows Kerberos (CVE-2022-37967), Kerberos RC4-HMAC (CVE-2022-37966), and Microsoft Exchange Server (CVE-2022-41080), as well as a denial-of-service flaw in Windows Hyper-V. (CVE-2022-38015).
Four RCE vulnerabilities in the Point-to-Point Tunneling Protocol (PPTP), all with CVSS scores of 8.1 (CVE-2022-41039, CVE-2022-41088, and CVE-2022-41044), and another affecting Windows scripting languages JScript9 and Chakra round out the list of Critical vulnerability remedies (CVE-2022-41118).
Aside from these concerns, the Patch Tuesday update fixes a variety of remote code execution flaws in the following apps:
Sharing is Caring!
You are welcome to put this blog article on your website, provided you also append an active link to our website "Source: https://rhyno.io"
For media enquiries, contact us at [email protected].
About Rhyno Cybersecurity Services
Rhyno Cybersecurity is a Canadian-based company focusing on 24/7 Managed Detection and Response, Penetration Testing, Enterprise Cloud, and Cyber Security Awareness Training Solutions for small and midsize businesses.
Our products and services are robust, innovative, and cost-effective. Underpinned by our 24x7x365 Security Operations Centre (SOC), our experts ensure you have access to cyber security expertise when you need it the most.
Frank anthony salon be
1 年Frank Anthony @frankanthonysalonbe C/o trattoria Cosenza Inc. Thank you
Digital Marketing Specialist
2 年Thanks Dan!
Storage Specialist @ IBM | |Data Resiliency | Storage modernization and| HW Lifecycle Consultant
2 年Thank you!
Technology Delivery | Mitigation | Innovation | TPRM | Global IT Enterprise | Integration | Change | GRC | Cyber | RFP | M&A | Diligence | Strategy | Transformation | Modernization
2 年Thank you