ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-21972
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.1
group max
79%
  • microsoft windows 10
  • microsoft windows 11
  • microsoft windows 7
  • +1 more
CVE-2022-26923
Authenticated Privilege Escalation in Microsoft Active Directory Domain Services

CVE-2022-26923 is an elevation-of-privilege flaw in Microsoft Active Directory Domain Services (CWE-295, improper certificate validation), widely known as the 'sAMAccountName spoofing' issue. An attacker with ordinary domain-user credentials can create or rename a computer account so its sAMAccountName matches a domain controller's name, obtain a certificate for that account, and use the flawed certificate-to-account name mapping to authenticate as that domain controller. Successful exploitation grants the attacker Domain Admin privileges and effectively full control over the Active Directory forest. Any organization running AD DS on the affected Windows 10/11, Windows 8.1, Windows RT 8.1, or Windows Server releases is exposed until patched. The flaw was fixed in Microsoft's May 2022 Patch Tuesday updates and is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-08-18, EPSS puts its 30-day exploitation probability at 83.5% (100th percentile), no public PoC is cataloged, and ransomware use is unknown.

Do: Apply Microsoft's May 2022 security updates (or later cumulative updates) to every domain controller and affected Windows/Windows Server host, prioritizing domain controllers, and verify patch status fleet-wide. Until patched, audit recently created or renamed computer accounts whose sAMAccountName matches a domain controller name, restrict which users can add machine accounts, and monitor for unusual certificate-based logons by privileged accounts. Patching is required for U.S. federal agencies since the flaw is in CISA's KEV catalog (required action: apply updates per vendor instructions).

8.884% KEV
  • Microsoft Active Directory Domain Services (CISA: Microsoft Active Directory) AD DS on supported Windows and Windows Server releases
  • Microsoft Windows 10 1507, 1607, 1809, 1909, 20H2, 21H1, 21H2
  • Microsoft Windows 11 21H2
  • +4 more
massmillions of domain-joined systems across effectively all enterprise AD forests that had not yet applied the May 2022 updates
CVE-2022-26937
Windows Network File System Remote Code Execution Vulnerability

Windows Network File System Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.876%
  • microsoft windows server
  • microsoft windows server 2008
  • microsoft windows server 2012
  • +1 more
CVE-2022-29108
Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft SharePoint Server Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.812%
  • microsoft sharepoint enterprise server
  • microsoft sharepoint foundation
  • microsoft sharepoint server
CVE-2022-29972
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift ODBC Driver (1.4.14 through 1.4.21.1001

An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift ODBC Driver (1.4.14 through 1.4.21.1001 and 1.4.22 through 1.4.x before 1.4.52) may allow a local user to execute arbitrary code.

NVD description · AI analysis pending
7.84%
  • insightsoftware magnitude simba amazon redshift odbc driver
Full article465 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, May 10, 2022 15:31

Microsoft returned to its normal monthly patching volume in May, disclosing and fixing 74 vulnerabilities as part of the company’s latest security update. This month’s Patch Tuesday includes seven critical vulnerabilities after Microsoft disclosed more than 140 security issues in April.

The point-to-point tunneling feature in Windows contains two of the most serious vulnerabilities that could allow an attacker to execute remote code on a targeted RAS server machine. While CVE-2022-21972 and CVE-2022-23270 are rated “critical,” Microsoft stated the attack complexity is high since an adversary needs to win a race condition, making it less likely an attacker could exploit these issues.

CVE-2022-26931 and CVE-2022-26923 are elevation of privilege vulnerabilities in Windows Kerberos and Windows Active Directory, respectively. They both are considered critical, though CVE-2022-26931 is considered less likely to be exploited because it has a higher attack complexity.

The Windows Network File System contains the highest-rated vulnerability of the month: CVE-2022-26937, which has a severity score of 9.8 out of a possible 10. An attacker could exploit this vulnerability by making an unauthenticated, specially crafted call to an NFS service to eventually gain the ability to execute remote code.

May’s Patch Tuesday also features a vulnerability in the Magnitude Simba Amazon Redshift ODBC Driver that affects the Windows self-hosted integration runtime service. An attacker could exploit CVE-2022-29972 to execute remote code, though they would need to first have the same level of privilege as a Synapse Administrator, Synapse Contributor or Synapse Computer Operator.

Talos would also like to highlight six important vulnerabilities that Microsoft considers to be “more likely” to be exploited:

A complete list of all the vulnerabilities Microsoft disclosed this month is available on its update page.

In response to these vulnerability disclosures, Talos is releasing a new SNORTⓇ rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Cisco Secure Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.

The rules included in this release that protect against the exploitation of many of these vulnerabilities are 59726 - 59728, 59730, 59731, 59733, 59734, 59737 and 59738. For Snort 3, the following rules are also available to protect against these vulnerabilities: 300125, 300126, 300128, 300129, 300130, 300133 and 300134 - 300137.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-for-may-2022/