ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Two Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-41076
PowerShell Remote Code Execution Vulnerability

PowerShell Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.561%
  • microsoft powershell
  • microsoft windows 10
  • microsoft windows 11
  • +1 more
CVE-2022-44693
Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft SharePoint Server Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.82%
  • microsoft sharepoint enterprise server
  • microsoft sharepoint foundation
  • microsoft sharepoint server
CVE-2022-44698
SmartScreen Security Feature Bypass in Windows 10/11 and Windows Server

CVE-2022-44698 is a security feature bypass in Microsoft Defender SmartScreen in which specially crafted files do not properly trigger the SmartScreen Mark-of-the-Web warning prompt. The flaw is triggered over the network but requires user interaction: an attacker typically delivers a crafted file via a malicious link or phishing email, and when the user clicks or opens it, SmartScreen fails to show its usual warning. An attacker gains the ability to run malicious content on a user's machine without the standard SmartScreen prompt, making the flaw an effective delivery and initial-access aid — it has documented use in ransomware campaigns. Anyone running the affected Windows releases is exposed: Windows 10 versions 1607 through 22H2, Windows 11 21H2, and Windows Server 2016, 2019, and 2022. The vulnerability was exploited as a zero-day before patching, was added to CISA's Known Exploited Vulnerabilities catalog on 2022-12-13 with known ransomware use, and Google reported a ransomware gang abusing it in the wild.

Do: Apply Microsoft's December 2022 security updates (or any later cumulative updates) for Windows 10, Windows 11, and Windows Server, prioritizing user workstations and systems exposed to phishing or web downloads, per the CISA KEV required action. Until patched, reinforce user awareness that downloaded files may not trigger the usual SmartScreen warning, and consider restricting download or execution of risky file types. Confirm remediation against CISA KEV guidance and treat this as high-priority given known ransomware exploitation.

5.476% KEV ransomware
  • microsoft Windows 10 1607, 1809, 20H2, 21H1, 21H2, 22H2
  • microsoft Windows 11 21H2
  • microsoft Windows Server 2016, 2019, 2022
  • +1 more
masshundreds of millions of Windows endpoints (SmartScreen is built into every affected Windows 10/11 and Windows Server installation)
CVE-2022-44710
DirectX Graphics Kernel Elevation of Privilege Vulnerability

DirectX Graphics Kernel Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.8<1%
  • microsoft windows 11

Indicators of compromiseAll →

TypeIndicatorContext
domainshutterstock.comarePoint server.” Editorial credit icon image: Paolo Bona / Shutterstock.com
Full article386 words · extracted from infosecurity-magazine.com · click to collapse

The final Microsoft Patch Tuesday of 2022 addressed nearly a half century of vulnerabilities including two zero-days, one of which is being exploited in the wild.

A handful of the bugs are rated “critical” while 13 are described by Microsoft as “more likely to be exploited,” meaning there’s still plenty of work to do for sysadmins at the end of the year.

The zero-day that is currently being exploited is CVE-2022-44698 – a security feature bypass vulnerability in Windows SmartScreen. This tool works with the vendor’s Mark of the Web (MOTW) functionality which flags files downloaded from the internet, according to Satnam Narang, senior staff research engineer at Tenable.

“This vulnerability can be exploited in multiple scenarios, including through malicious websites and malicious attachments delivered over email or messaging services,” he added.

“They require a potential victim to visit the malicious website or open a malicious attachment in order to bypass SmartScreen.”

However, the proof-of-concept code for the bug is not thought to have been publicly disclosed as yet.

The second zero-day is CVE-2022-44710 – an elevation of privilege vulnerability in the DirectX Graphics Kernel which was publicly disclosed prior to a patch becoming available, but is not yet being exploited.

“It is considered to be a flaw that is less likely to be exploited based on Microsoft’s Exploitability Index,” confirmed Narang.

Mike Walters, VP of vulnerability and threat research at Action1, pointed to critical PowerShell vulnerability CVE-2022-41076 as worthy of attention. It affects all Windows OS versions from Windows 7 and Windows Server 2008 R2 on.

“This critical vulnerability has a high CVSS risk score of 8.5, because any authenticated user can trigger the vulnerability and run unapproved PowerShell commands execution in the target system, even though the exploitation does require some preparation from the attacker,” Walters explained.

CVE-2022-44693 is a critical remote code execution vulnerability in SharePoint with a CVSS score of 8.8. Crucially it’s of low complexity and requires no privilege escalation.

“To exploit it, attackers only need access to the basic user account with Manage List permissions, which most companies grant to all SharePoint users by default,” warned Walters.

“This vulnerability does not require user interaction; once attackers get the appropriate credentials, they can execute code remotely on a target SharePoint server.”

Editorial credit icon image: Paolo Bona / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/two-zerodays-fixed-december-patch/