Two Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-41076 | PowerShell Remote Code Execution Vulnerability PowerShell Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.5 | 61% |
| — | ||
| CVE-2022-44693 | Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2022-44698 | SmartScreen Security Feature Bypass in Windows 10/11 and Windows Server CVE-2022-44698 is a security feature bypass in Microsoft Defender SmartScreen in which specially crafted files do not properly trigger the SmartScreen Mark-of-the-Web warning prompt. The flaw is triggered over the network but requires user interaction: an attacker typically delivers a crafted file via a malicious link or phishing email, and when the user clicks or opens it, SmartScreen fails to show its usual warning. An attacker gains the ability to run malicious content on a user's machine without the standard SmartScreen prompt, making the flaw an effective delivery and initial-access aid — it has documented use in ransomware campaigns. Anyone running the affected Windows releases is exposed: Windows 10 versions 1607 through 22H2, Windows 11 21H2, and Windows Server 2016, 2019, and 2022. The vulnerability was exploited as a zero-day before patching, was added to CISA's Known Exploited Vulnerabilities catalog on 2022-12-13 with known ransomware use, and Google reported a ransomware gang abusing it in the wild. Do: Apply Microsoft's December 2022 security updates (or any later cumulative updates) for Windows 10, Windows 11, and Windows Server, prioritizing user workstations and systems exposed to phishing or web downloads, per the CISA KEV required action. Until patched, reinforce user awareness that downloaded files may not trigger the usual SmartScreen warning, and consider restricting download or execution of risky file types. Confirm remediation against CISA KEV guidance and treat this as high-priority given known ransomware exploitation. | 5.4 | 76% | KEV ransomware |
| masshundreds of millions of Windows endpoints (SmartScreen is built into every affected Windows 10/11 and Windows Server installation) | |
| CVE-2022-44710 | DirectX Graphics Kernel Elevation of Privilege Vulnerability DirectX Graphics Kernel Elevation of Privilege Vulnerability NVD description · AI analysis pending | 7.8 | <1% |
| — |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | shutterstock.com | arePoint server.” Editorial credit icon image: Paolo Bona / Shutterstock.com |
Full article386 words · extracted from infosecurity-magazine.com · click to collapse
The final Microsoft Patch Tuesday of 2022 addressed nearly a half century of vulnerabilities including two zero-days, one of which is being exploited in the wild.
A handful of the bugs are rated “critical” while 13 are described by Microsoft as “more likely to be exploited,” meaning there’s still plenty of work to do for sysadmins at the end of the year.
The zero-day that is currently being exploited is CVE-2022-44698 – a security feature bypass vulnerability in Windows SmartScreen. This tool works with the vendor’s Mark of the Web (MOTW) functionality which flags files downloaded from the internet, according to Satnam Narang, senior staff research engineer at Tenable.
“This vulnerability can be exploited in multiple scenarios, including through malicious websites and malicious attachments delivered over email or messaging services,” he added.
“They require a potential victim to visit the malicious website or open a malicious attachment in order to bypass SmartScreen.”
However, the proof-of-concept code for the bug is not thought to have been publicly disclosed as yet.
The second zero-day is CVE-2022-44710 – an elevation of privilege vulnerability in the DirectX Graphics Kernel which was publicly disclosed prior to a patch becoming available, but is not yet being exploited.
“It is considered to be a flaw that is less likely to be exploited based on Microsoft’s Exploitability Index,” confirmed Narang.
Mike Walters, VP of vulnerability and threat research at Action1, pointed to critical PowerShell vulnerability CVE-2022-41076 as worthy of attention. It affects all Windows OS versions from Windows 7 and Windows Server 2008 R2 on.
“This critical vulnerability has a high CVSS risk score of 8.5, because any authenticated user can trigger the vulnerability and run unapproved PowerShell commands execution in the target system, even though the exploitation does require some preparation from the attacker,” Walters explained.
CVE-2022-44693 is a critical remote code execution vulnerability in SharePoint with a CVSS score of 8.8. Crucially it’s of low complexity and requires no privilege escalation.
“To exploit it, attackers only need access to the basic user account with Manage List permissions, which most companies grant to all SharePoint users by default,” warned Walters.
“This vulnerability does not require user interaction; once attackers get the appropriate credentials, they can execute code remotely on a target SharePoint server.”
Editorial credit icon image: Paolo Bona / Shutterstock.com
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/two-zerodays-fixed-december-patch/