Microsoft Patch Tuesday for Feb. 2022 — Snort rules and prominent vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-22715 | Named Pipe File System Elevation of Privilege Vulnerability Named Pipe File System Elevation of Privilege Vulnerability NVD description · AI analysis pending | 7.8 group max | 13% |
| — | ||
| CVE-2022-21996 | Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability NVD description · AI analysis pending | 7.8 | 3% |
| — | ||
| CVE-2022-21999 | Local Privilege Escalation in Microsoft Windows Print Spooler (CISA KEV) CVE-2022-21999 is a privilege elevation vulnerability in the Windows Print Spooler service, caused by improper encapsulation of resources (CWE-40), which lets a local, limited-privilege user manipulate spooler resource handling and execute code with elevated rights. An attacker gains SYSTEM-level privileges on the affected Windows host after already obtaining some foothold locally, making it a common post-compromise escalation step rather than a remote entry point. Any Windows system with the Print Spooler service enabled — the default on most Windows desktop and server installations — is affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-25 with known ransomware use, and EPSS assigns a 41.7% chance of exploitation within 30 days (99th percentile), while the source data records no public proof-of-concept. Required action per CISA is to apply Microsoft updates per vendor instructions. Do: Apply the vendor security updates per Microsoft's instructions, as required by CISA's KEV listing; since the source data does not specify fixed versions, verify your current Windows build against Microsoft's advisory. As an interim mitigation, disable the Print Spooler service on hosts where local or shared printing is not required. Because the flaw is exploited in the wild and linked to ransomware, check spooler-related privilege escalation activity in logs and prioritize patching servers and workstations accessible to low-privileged users. | 7.8 | 42% | KEV ransomware |
| masshundreds of millions of Windows devices (Print Spooler enabled by default on most desktop/server installs) | |
| CVE-2022-22005 | Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.8 | 16% |
| — |
Full article315 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, February 8, 2022 13:57
Microsoft released its monthly security update Tuesday, disclosing 51 vulnerabilities across its large collection of hardware and software.
None of the vulnerabilities disclosed this month are considered “critical,” an extreme rarity for the company’s Patch Tuesdays. Additionally, none of the issues Microsoft patched have been exploited in the wild to this point, nor have they been publicly disclosed.
There are still a few vulnerabilities of note, however, including CVE-2022-21997, CVE-2022-21999 and CVE-2022-22715, which are all privilege elevation vulnerabilities in the Microsoft print spooler service. In the event an exploit is developed, an adversary could use these vulnerabilities to execute code as a system user or higher-level privileges.
There are four other similar vulnerabilities that could allow attackers to escalate their privileges:
- CVE-2022-21989 — Windows Kernel
- CVE-2022-21994 — Windows DWM Core Library
- CVE-2022-21996 — Win32k
- CVE-2022-22715 — Named Pipe File
Though considered to be of “important” severity, CVE-2022-22005 is a remote code execution vulnerability in SharePoint that received a severity score of 8.8 out of 10. An adversary would need to be authenticated and possess correct permissions for page creation to exploit this vulnerability.
A complete list of all the vulnerabilities Microsoft disclosed this month is available on its update page.
In response to these vulnerability disclosures, Talos is releasing a new SNORTⓇ rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Cisco Secure Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.
The rules included in this release that protect against the exploitation of many of these vulnerabilities are 58993, 58994, 58999 - 59002 and 59004 - 59009.
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-for-feb-2022/