ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Microsoft Fixes Three Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-22012
+2 in the same advisory: …29130 …22713
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.8
group max
4%
  • microsoft windows 10
  • microsoft windows 11
  • microsoft windows 7
  • +1 more
CVE-2022-26925
Spoofing Flaw in Windows LSA (CVE-2022-26925) Exploited Against Domain Controllers

CVE-2022-26925 is a spoofing vulnerability in the Windows Local Security Authority (LSA) that lets an unauthenticated network attacker make a spoofed call to LSA on a remote Windows host. It is triggered over the network with no user interaction, typically by coercing a Windows system—most critically a domain controller—into authenticating via NTLM to an attacker-controlled machine, in the manner of the PetitPotam forced-authentication attacks referenced in CISA's catalog update. By spoofing the client when LSA processes that authentication, the attacker undermines NTLM's authentication guarantees and, when chained with relay techniques, can authenticate to a domain controller with elevated privileges, which is reflected in the CVSS high-integrity impact. Any organization running affected Windows clients or Windows Server versions is exposed, with domain controllers the highest-value targets. The flaw was exploited as a zero-day before Microsoft's June 2022 Patch Tuesday fixes and is now listed in CISA's Known Exploited Vulnerabilities catalog, with CISA ordering federal agencies to patch.

Do: Apply Microsoft's June 2022 Patch Tuesday updates (per CISA's guidance for the June Microsoft patch, https://www.cisa.gov/guidance-applying-june-microsoft-patch) across all affected Windows versions, prioritizing domain controllers; systems that cannot yet patch should be protected with NTLM-related mitigations (e.g., enforced SMB signing, LDAP signing/channel binding, and restricting or auditing NTLM use) per CISA/Microsoft remediation guidance. Check whether domain controllers are internet-exposed or reachable from untrusted networks, and hunt for signs of forced-authentication/relay activity. Note that a related PetitPotam KEV entry was superseded, so ensure this newer LSA fix—not just the older PetitPotam patch—is deployed.

5.911% KEV
  • microsoft windows 10 1507, 1607, 1809, 1909, 20H2, 21H1, 21H2
  • microsoft windows 11 21H2
  • microsoft windows 7
  • +3 more
mass≈1 billion+ Windows installations worldwide (essentially every Windows environment, and domain controllers at virtually every Windows-running organization)
CVE-2022-29972
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift ODBC Driver (1.4.14 through 1.4.21.1001

An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift ODBC Driver (1.4.14 through 1.4.21.1001 and 1.4.22 through 1.4.x before 1.4.52) may allow a local user to execute arbitrary code.

NVD description · AI analysis pending
7.84%
  • insightsoftware magnitude simba amazon redshift odbc driver
Full article318 words · extracted from infosecurity-magazine.com · click to collapse

Microsoft has issued fixes for three zero-day vulnerabilities, including one being actively exploited in the wild, as part of its May monthly update round.

Publicly disclosed flaw CVE-2022-26925 is a spoofing vulnerability in Windows LSA marked as “exploitation detected.”

“The vulnerability by itself is only rated as important by Microsoft, has a CVSS v3.1 score of 8.1, and the exploit code maturity is listed as unproven, but dig a bit deeper and the vulnerability is much more threatening,” argued Ivanti VP of product management, Chris Goettl.

“The vulnerability has been detected in attacks, so while code samples available publicly may be unproven there are working exploits being used.”

He added that, when combined with NTLM relay attacks on Active Directory Certificate Services, the bug gets a combined CVSS score of 9.8. That’s why Microsoft is urging firms to patch all domain controllers as soon as possible.

The other two publicly disclosed flaws fixed this month have not yet been detected as exploited in the wild, although that may soon change.

CVE-2022-29972 is a critical remote code execution (RCE) vulnerability in Insight Software’s Magnitude Simba Amazon Redshift ODBC Driver. It will probably need to be patched by organizations’ cloud providers, according to Recorded Future senior security architect Allan Liska.

The final zero-day is CVE-2022-22713, a denial of service vulnerability in Hyper-V.

“This vulnerability appears to be limited to Windows 10 on X64-based systems and Windows Server 2019,” said Liska.

“Microsoft rates this vulnerability as Important with a CVSS score of 5.6 and deems it ‘Exploitation Less Likely.’ That being said, because it is publicly disclosed those organizations reliant on Hyper-V for remote connectivity and management should prioritize patching.”

Liska also drew attention to critical RCE LDAP vulnerabilities CVE-2022-22012 and CVE-2022-29130, which have CVSS scores of 9.8.

If users have the MaxReceiveBuffer LDAP policy set to a value higher than the default, they should prioritize patching, he said.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-three-zerodays-may-patch/