Microsoft Starts 2022 with 97 CVEs in January Patch Tuesday
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-22947 | When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server. NVD description · AI analysis pending | 5.9 | 3% | PoC |
| — | |
| CVE-2021-36976 | libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block). libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block). NVD description · AI analysis pending | 6.5 | 3% |
| — | ||
| CVE-2022-21874 | Windows Security Center API Remote Code Execution Vulnerability Windows Security Center API Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2022-21919 | Local Privilege Escalation in Microsoft Windows User Profile Service The Windows User Profile Service contains a link-following flaw (CWE-59) that lets an authenticated local attacker with low privileges elevate to SYSTEM/administrator rights, typically by planting a junction or symlink that the service follows while handling user profile operations. The attack is local-only (AV:L) with high attack complexity and no user interaction required, so it cannot be exploited remotely or by unauthenticated users. Any environment running the affected Windows releases — Windows 7, 8.1, RT 8.1, Windows 10 versions 1507 through 21H2, Windows 11 21H2, and Windows Server 2008 per the CPE data — is exposed wherever standard users can execute code. Microsoft shipped the fix in its January 2022 Patch Tuesday release, and CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2022-04-25, confirming exploitation in the wild. Ransomware association is not documented, and no public proof-of-concept is known; EPSS currently puts 30-day exploitation probability at 3.0% (86th percentile). Do: Apply Microsoft's January 2022 Patch Tuesday security updates (or any later cumulative/LC updates) to all affected Windows 7/8.1/10/11 clients, Windows RT 8.1 devices, and Windows Server 2008 systems, per CISA's required action. Windows 7/8.1/Server 2008 may require Extended Security Updates where mainstream support has ended. Prioritize hosts that expose interactive logon to untrusted or low-privilege users and verify patch compliance, given the KEV listing confirms active exploitation. | 7.0 | 3% | KEV |
| masshundreds of millions of Windows endpoints and servers (Windows 10/11 installed base is on the order of one billion devices; unpatched share unknown) |
Full article358 words · extracted from infosecurity-magazine.com · click to collapse
Microsoft began the year by publishing fixes for nearly a century of vulnerabilities, nine of which were rated critical and six of which were publicly disclosed.
The Windows OS updates issued this month will fix all of the known bugs, according to Ivanti VP of product management, Chris Goettl.
“While there are no known exploited vulnerabilities this month, the six publicly disclosed vulnerabilities may warrant more immediate attention as they could have exposed proof-of-concept code or other details that can give adversaries additional details to develop an exploit,” he warned.
These include: CVE-2022-21839, a denial of service vulnerability in the Windows event tracing discretionary access control list; an elevation of privilege flaw in Windows user profile service (CVE-2022-21919); and a Windows certificates spoofing vulnerability (CVE-2022-21836).
The remaining three publicly disclosed flaws are remote code execution bugs in Windows Security Center API (CVE-2022-21874), libarchive (CVE-2021-36976) and open source curl (CVE-2021-22947).
According to Automox, this month’s Patch Tuesday has the highest number of critical CVEs since July 2021.
There’s plenty more to keep sysadmins busy. Mozilla resolved 18 CVEs, including nine rated critical in three updates, impacting Mozilla Thunderbird, Firefox and Firefox ESR. Adobe issued five updates resolving 41 vulnerabilities, 22 of which are rated as critical.
There’s also more to come, with Oracle’s quarterly Critical Patch Update set to land next week.
All of this comes as organizations continue to hunt for vulnerable Log4j instances in their IT ecosystem, many of which may be hidden by complex Java dependencies.
“Organizations that were able to respond quickly found that truly understanding their exposure required rolling up their sleeves. They quickly assessed their internal development teams for use of Log4j and their vendor risk management process to determine what vendors they were consuming solutions from and assessing each to determine if they were exposed,” explained Goettl.
“As an additional step, security teams also utilized a variety of custom scanners purpose-built to scan for the Log4j binaries. This is crucial given Log4j was buried many cases in a few layers of JAR files which was throwing many vulnerability scanners off.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-starts-2022-with-97-cves/