April 2022 Patch Tuesday forecast: Spring is in the air (and vulnerable)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-22675 +1 in the same advisory: …22674 | Out-of-Bounds Write in Apple macOS/iOS Kernel Allows Arbitrary Code Execution CVE-2022-22675 is an out-of-bounds write vulnerability (CWE-787) in the Apple kernel, addressed through improved bounds checking. It is triggered locally — the CVSS vector shows a local attack vector with user interaction, meaning an application running on the device can trigger the memory corruption. Successful exploitation allows an application to execute arbitrary code with kernel privileges, giving the attacker full control over the affected device. Users of iPhone, iPad, Mac, Apple TV, and Apple Watch running versions prior to the fixed releases are affected. Apple reported that the issue may have been actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-04-04. Do: Update to iOS/iPadOS 15.4.1, macOS Monterey 12.3.1 or macOS Big Sur 11.6.6, tvOS 15.5, and watchOS 8.6 as required by CISA. Because the flaw is exploited in the wild and requires only a malicious local application, prioritize patching user-facing iPhone, iPad, and Mac fleets first. There is no public PoC; verify installed OS versions on managed devices and confirm remediation after the updates are applied. | 7.8 group max | 12% | KEV |
| mass≈1 billion+ active Apple devices across iPhone, iPad, Mac, Apple TV, and Apple Watch | |
| CVE-2022-22965 | Unauthenticated RCE in VMware Spring Framework (Spring4Shell) - JDK 9+ Tomcat WARs CVE-2022-22965 ('Spring4Shell') is a critical (CVSS 9.8) remote code execution flaw in VMware's Spring Framework, caused by insecure data binding that lets unauthenticated attackers overwrite internal class and module properties through crafted request parameters (CWE-94, code injection). It affects Spring MVC and Spring WebFlux applications running on JDK 9 or later; the demonstrated exploit path requires a Tomcat WAR deployment, while applications packaged as Spring Boot executable jars are not exploitable that way, though the underlying issue may be reachable via other routes. A successful attack yields full remote code execution with the privileges of the application server, with no authentication or user interaction required. VMware Spring Framework 5.3.0-5.3.17 and 5.2.0-5.2.19 (plus older releases) are affected, and the flaw also impacts bundled products from Cisco, Oracle, Siemens and Veritas, including multiple Oracle Communications Cloud Native Core components. It is being actively exploited in the wild: added to CISA's KEV on 2022-04-04, EPSS puts 30-day exploitation probability at 99.6% (100th percentile), a public PoC is available, and mass scanning of vulnerable servers has been observed. Do: Upgrade Spring Framework to 5.3.18, 5.2.20 or later (or apply vendor-supplied fixes for bundled products, e.g., via Oracle's patch release and Cisco's advisory), prioritizing internet-facing Tomcat WAR deployments on JDK 9+; this is a CISA KEV entry, so treat patching as urgent. If patching must wait, mitigate by running on JDK 8, deploying as a Spring Boot executable jar rather than a WAR on Tomcat, and applying the vendor-documented workaround that disallows 'class.*', 'Class.*' and 'module.*' fields in data binding. Inventory exposed Tomcat/Spring services and hunt for signs of exploitation given confirmed in-the-wild use. | 9.8 | 100% | KEV PoC |
| massmass - on the order of 1M+ Spring-based Java deployments overall, with at least ~100,000 internet-exposed Tomcat servers on JDK 9+ plausibly meeting the… |
Full article662 words · extracted from helpnetsecurity.com · click to collapse
March Patch Tuesday releases followed in the footsteps of February with low numbers of CVEs reported and resolved, and all updates rated as important except one critical update for Microsoft Exchange Server. Could April Patch Tuesday provide the deluge of critical updates we were expecting last month?

Security enhancements for Windows 11
Microsoft has clearly been busy working on security improvements in multiple arenas. Earlier this week, they announced an extensive set of security enhancements for Windows 11, providing protection for what they call ‘chip to cloud’. These new features and enhancements take advantage of hardware assistance from the new Pluton Security Processor at the chip level all the way up to cloud protection via the Windows Defender SmartScreen to prevent phishing and malware injection from malicious websites.
Other security features covered include Credential Guard, Config Lock, Personal Data Protection, and Hypervisor-Protected Code Integrity (HVCI) default enhancements. Microsoft also announced their upcoming Autopatch service targeted at Windows Enterprise E3 customers. Based on the comments from multiple sites, there’s some concern over who really needs this, so we’ll see how it plays out when available.
Spring4Shell
There were a lot of hot vulnerabilities this month, with CVE-2022-22965, also known as Spring4Shell or SpringShell, in the Spring Framework being the hottest. The Spring Framework is a Java platform used to support Java application development.
Latest reports show that while many platforms may contain this vulnerability, only a small percentage are open to exploitation due to specific environmental configuration. Regardless, like Log4j, you should scan your systems and update to the latest version to get the fix in place.
Apple and VMware
Apple announced two zero-day vulnerabilities, CVE-2022-22675 and CVE-2022-22674, and provided iOS 15 and Monterey updates. We’re still waiting on updates for Catalina and Big Sur.
And one final notification worth mentioning came from VMware in VMSA-2022-011. These eight vulnerabilities impacted multiple versions of five different products, including VMware Workspace ONE Access. Five of the vulnerabilities are rated critical and have CVSS scores from 9.1 to 9.8. Unlike the Spring and Apple vulnerabilities, these eight have not been reported as being exploited in the wild. If you haven’t been following all the action in March and early April, plan on identifying and including the applicable updates for these products in your Patch Tuesday rollout.
CISA catalog
I’ll mention again this month that the US Cybersecurity and Infrastructure Security Agency is continuing its strong response to heightened Russian activity adding known exploited vulnerabilities at regular intervals. There are now 616 entries in their catalog. While mandatory for government agencies to address the vulnerabilities by the dates shown, this catalog provides a good starting point for anyone looking for high priority vulnerabilities to identify on their systems and fix.
April 2022 Patch Tuesday forecast
- Plan for more critical updates this month; I don’t see the trend of only important ones continuing. Operating system updates will include the Extended Security Updates (ESUs) for Windows 7 and Server 2008. I hope you are working towards migration to a newer OS as they end in January. Microsoft Office and Exchange Server will see some minor updates.
- Adobe is due for a major update of Acrobat and Reader but there hasn’t been a pre-announcement yet.
- The zero-day release for iOS 15 and Monterey is out, so be on the lookout for similar updates for Catalina and Big Sur soon.
- Google released Long Term Support Channel 96.0.4664.204 for ChromeOS devices containing three High-rated vulnerabilities on Wednesday. The Stable Channel Update for Desktop 100.0.4896.75 for Windows, Mac and Linux was released on Monday. This update includes only one security fix rated High.
- Mozilla released updates for Firefox 99, Firefox ESR 91.8, and Thunderbird 91.8 on Wednesday. Don’t expect any new updates next week.
Don’t forget the Oracle Critical Product Update (CPU) is coming next week on April 19th. With all this Java-related activity from Log4j and Spring, we may see a large set of CVEs in that release.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/04/08/april-2022-patch-tuesday-forecast/