ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

No Critical CVEs Addressed in February Patch Tuesday

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-21989
+2 in the same advisory: …21997 …22717
Windows Kernel Elevation of Privilege Vulnerability

Windows Kernel Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.8
group max
3%
  • microsoft windows 10
  • microsoft windows 11
  • microsoft windows 7
  • +1 more
CVE-2022-21999
+1 in the same advisory: …22718
Local Privilege Escalation in Microsoft Windows Print Spooler (CISA KEV)

CVE-2022-21999 is a privilege elevation vulnerability in the Windows Print Spooler service, caused by improper encapsulation of resources (CWE-40), which lets a local, limited-privilege user manipulate spooler resource handling and execute code with elevated rights. An attacker gains SYSTEM-level privileges on the affected Windows host after already obtaining some foothold locally, making it a common post-compromise escalation step rather than a remote entry point. Any Windows system with the Print Spooler service enabled — the default on most Windows desktop and server installations — is affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-25 with known ransomware use, and EPSS assigns a 41.7% chance of exploitation within 30 days (99th percentile), while the source data records no public proof-of-concept. Required action per CISA is to apply Microsoft updates per vendor instructions.

Do: Apply the vendor security updates per Microsoft's instructions, as required by CISA's KEV listing; since the source data does not specify fixed versions, verify your current Windows build against Microsoft's advisory. As an interim mitigation, disable the Print Spooler service on hosts where local or shared printing is not required. Because the flaw is exploited in the wild and linked to ransomware, check spooler-related privilege escalation activity in logs and prioritize patching servers and workstations accessible to low-privileged users.

7.842% KEV ransomware
  • Microsoft Windows (Print Spooler service)
masshundreds of millions of Windows devices (Print Spooler enabled by default on most desktop/server installs)
CVE-2022-22005
Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft SharePoint Server Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.816%
  • microsoft sharepoint enterprise server
  • microsoft sharepoint foundation
  • microsoft sharepoint server
Full article320 words · extracted from infosecurity-magazine.com · click to collapse

System administrators were blessed with a relatively quiet Patch Tuesday this week, after Microsoft released fixes for 48 CVEs, including one that had been publicly disclosed but not yet exploited.

CVE-2022-21989 is an elevation of privilege vulnerability in the Windows kernel that was previously disclosed. It impacts Windows 7-11 and Windows Server 2008-2022.

“While Microsoft has not observed exploitation of this vulnerability, they do assess the vulnerability as ‘Exploitation More Likely,’ meaning that exploitation of the vulnerability is highly probable and that it should be prioritized for patching,” argued Recorded Future’s senior security architect, Allan Liska.

He also urged admins to address CVE-2022-22005, a remote code execution vulnerability in Microsoft’s Sharepoint Server.

Although labeled “important,” it also has an exploitation assessment of “Exploitation More Likely.” It affects SharePoint Server versions 2013-2019 and the SharePoint Server Subscription Edition.

“The vulnerability does require an attacker to be authenticated in order to exploit it, which is likely why Microsoft only labeled it ‘important.’ However, given the number of stolen credentials readily available on underground markets, getting authenticated could be trivial,” argued Liska.

“Organizations that have public-facing SharePoint servers should prioritize implementing this patch.”

Elsewhere, Ivanti product management VP, Chris Goettl, pointed to four CVEs in Windows Print Spooler, allowing elevation of privileges: CVE-2022-21999CVE-2022-21997CVE-2022-22718, and CVE-2022-22717.

“Three of these vulnerabilities had acknowledgments to external researchers. This indicates two things. First that Print Spooler still has a bit of exposure being cleaned up post Print Nightmare and second that there are several external white hat researchers still digging in so you can bet threat actors are likely doing the same,” he explained.

“Also, there were several changes to Print Spooler, so test your printer functionality well this cycle.”

Unusually for Microsoft’s monthly security update round, none of the vulnerabilities addressed were rated critical. However, organizations should always prioritize CVEs for patching according to their own particular risk assessments. 

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/no-critical-cves-february-patch/