ZeroHour
Cisco Talospublished ()ingested

Microsoft Patch Tuesday for July 2022 — Snort rules and prominent vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-22029
+1 in the same advisory: …22039
Windows Network File System Remote Code Execution Vulnerability

Windows Network File System Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.1
group max
5%
  • microsoft windows server 2008
  • microsoft windows server 2012
  • microsoft windows server 2016
  • +1 more
CVE-2022-30216
+4 in the same advisory: …22038 …22034 …30220 …30202
Windows Server Service Tampering Vulnerability

Windows Server Service Tampering Vulnerability

NVD description · AI analysis pending
8.8
group max
89%
  • microsoft windows 10
  • microsoft windows 11
  • microsoft windows server 2016
  • +1 more
CVE-2022-22047
Local Privilege Escalation in Windows CSRSS Affects Nearly All Windows Versions

CVE-2022-22047 is an elevation-of-privilege vulnerability in the Windows Client Server Run-time Subsystem (CSRSS), a core user-mode process that handles console and system tasks, caused by an untrusted search path (CWE-426). An attacker who already has a low-privileged foothold on a Windows machine can trigger the flaw locally, with no user interaction, to elevate to SYSTEM/administrator-level privileges. Because CSRSS is present on essentially every Windows installation, the affected population spans Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 21H2), Windows 11 21H2, and Windows Server 2008 and 2012, meaning virtually every Windows desktop, laptop, and server in active use is potentially affected. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on July 12, 2022 with an August 2 patch deadline for federal agencies, and EPSS assigns it an 18.8% probability of exploitation within 30 days (97th percentile).

Do: Apply Microsoft's July 12, 2022 (Patch Tuesday) security updates immediately across all affected releases, including Windows 7, 8.1, RT 8.1, and Server 2008/2012, where fixes arrive through the same July update servicing; CISA's KEV deadline for federal agencies is August 2, 2022. Treat any host where a local attacker has executed code as potentially compromised to SYSTEM level, and hunt for post-exploitation activity. Keep monitoring vendor guidance, as recent reporting suggests some patched Windows attack surfaces may still be exploitable, so continue applying follow-on Windows updates as they ship.

7.819% KEV
  • microsoft Windows 10 1507
  • microsoft Windows 10 1607
  • microsoft Windows 10 1809
  • +9 more
mass≈1 billion+ Windows devices and servers (the affected list spans Windows 7 through Windows 11 and legacy server releases)
CVE-2022-30215
Active Directory Federation Services Elevation of Privilege Vulnerability

Active Directory Federation Services Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.52%
  • microsoft windows server 2016
  • microsoft windows server 2019
  • microsoft windows server 2022
CVE-2022-33646
Azure Batch Node Agent Elevation of Privilege Vulnerability

Azure Batch Node Agent Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.0<1%
  • microsoft azure batch
Full article502 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, July 12, 2022 13:33

Microsoft released its monthly security update Tuesday, disclosing more than 80 vulnerabilities in the company’s various software, hardware and firmware offerings, including one that’s actively being exploited in the wild.

July's security update features three critical vulnerabilities, up from one last month, still lower than Microsoft’s average in a Patch Tuesday. All the other vulnerabilities fixed are considered “important.”

All three critical vulnerabilities allow remote code execution on Microsoft Windows Systems. Of these, Microsoft considers the exploitation of CVE-2022-22029, CVE-2022-22038 and CVE-2022-22039 less likely to occur. CVE-2022-22029 could be exploited over the network by making an unauthenticated, specially crafted call to a Network File System (NFS). However, according to Microsoft, it has high attack complexity and would require repeated exploitation attempts through sending constant or intermittent data.

Another critical vulnerability, CVE-2022-22038, is also considered to be more difficult to exploit because it requires undisclosed additional actions by an attacker to prepare the target environment for exploitation.

CVE-2022-22039 iss another remote code execution flaw in Windows Network File System that requires an attacker to win a race condition to exploit it, making this vulnerability less likely to be exploited.

Microsoft Azure Batch Node Agent contains a remote code execution vulnerability: CVE-2022-33646. Microsoft considers this more likely to be exploited. However, the attack vector is identified as Local, which reduces its severity. It is worth mentioning that mitigating this vulnerability requires that a user follows the best practices advised by Microsoft and periodically resizes the azure node pools to zero to force the Agent to be updated to the latest version.

Of the vulnerabilities considered “important” and not critical, CVE-2022-22047 is worth special notice, as it is a local privilege escalation vulnerability reported as being actively exploited in the wild.

Talos would also like to highlight six important vulnerabilities that Microsoft considers to be “more likely” to be exploited:

  • CVE-2022-30202 — Windows Advanced Local Procedure Call Elevation of Privilege Vulnerability
  • CVE-2022-30215 — Active Directory Federation Services Elevation of Privilege Vulnerability
  • CVE-2022-30216 — Windows Server Service Tampering Vulnerability
  • CVE-2022-30220 — Windows Common Log File System Driver Elevation of Privilege Vulnerability
  • CVE-2022-22034 — Windows Graphics Component Elevation of Privilege Vulnerability A complete list of all the vulnerabilities Microsoft disclosed this month is available on its update page.

In response to these vulnerability disclosures, Talos is releasing a new Snort rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Cisco Secure Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.

The Snort 2 rules included in this release that protect against the exploitation of many of these vulnerabilities are 60191, 60192, 60198, 60199, 60201, 60202, 60206, 60207, 60213 and 60214. Additionally, users can deploy Snort 3 rules 300215 and 300216.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-for-july-2022/