Microsoft Patch Tuesday, October 2022 Edition
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-37968 | Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kubernetes cluster. Additionally, because Azure Stack Edge allows customers to deploy Kubernetes workloads on their devices via Azure Arc, Azure Stack Edge devices are also vulnerable to this vulnerability. NVD description · AI analysis pending | 10.0 | 3% |
| — | ||
| CVE-2022-41033 | Local Privilege Escalation in Microsoft Windows COM+ Event System Service CVE-2022-41033 is an elevation-of-privilege flaw in the Microsoft Windows COM+ Event System Service, classified under CWE-843 (access of a resource using an incompatible type). It is triggered locally: an attacker who can already execute code on a machine with limited (low-privilege) rights can exploit the vulnerable service with no user interaction, per the CVSS vector (AV:L/AC:L/PR:L/UI:N). Successful exploitation elevates the attacker to the highest local privilege level, with high impact on the confidentiality, integrity, and availability of the system — a typical post-compromise privilege-escalation step for an attacker who already has a foothold. The flaw affects the Windows releases in the CISA CPE data — Windows 7, 8.1, RT 8.1, Windows 10 (1507, 1607, 1809, 20H2, 21H1, 21H2), Windows 11 (21H2, 22H2), and Windows Server 2008 — meaning effectively the broad Windows installed base. Microsoft patched it in the October 2022 Patch Tuesday release and it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-11 as exploited in the wild; no public PoC is known, ransomware use is unknown, and EPSS currently estimates a 1.7% probability of exploitation in the next 30 days (75th percentile). Do: Apply the October 2022 Windows security updates (or any later cumulative update) on all affected Windows clients and servers, prioritizing hosts where low-privileged users can run code, such as workstations, terminal/RDS servers, and VDI images — this also satisfies the CISA KEV required action. Until patched, treat any unprivileged compromise of a Windows host as potentially escalated to full local privilege, and restrict untrusted local code execution where possible. Verify remediation by confirming the October 2022 (or newer) cumulative update level on each host rather than relying on OS version alone. | 7.8 | 2% | KEV |
| masson the order of 1 billion Windows devices (essentially the entire supported Windows client and server installed base) |
Full article700 words · extracted from krebsonsecurity.com · click to collapse
Microsoft today released updates to fix at least 85 security holes in its Windows operating systems and related software, including a new zero-day vulnerability in all supported versions of Windows that is being actively exploited. However, noticeably absent from this month’s Patch Tuesday are any updates to address a pair of zero-day flaws being exploited this past month in Microsoft Exchange Server.

The new zero-day flaw– CVE-2022-41033 — is an “elevation of privilege” bug in the Windows COM+ event service, which provides system notifications when users logon or logoff. Microsoft says the flaw is being actively exploited, and that it was reported by an anonymous individual.
“Despite its relatively low score in comparison to other vulnerabilities patched today, this one should be at the top of everyone’s list to quickly patch,” said Kevin Breen, director of cyber threat research at Immersive Labs. “This specific vulnerability is a local privilege escalation, which means that an attacker would already need to have code execution on a host to use this exploit. Privilege escalation vulnerabilities are a common occurrence in almost every security compromise. Attackers will seek to gain SYSTEM or domain-level access in order to disable security tools, grab credentials with tools like Mimkatz and move laterally across the network.
Indeed, Satnam Narang, senior staff research engineer at Tenable, notes that almost half of the security flaws Microsoft patched this week are elevation of privilege bugs.
Some privilege escalation bugs can be particularly scary. One example is CVE-2022-37968, which affects organizations running Kubernetes clusters on Azure and earned a CVSS score of 10.0 — the most severe score possible.
Microsoft says that to exploit this vulnerability an attacker would need to know the randomly generated DNS endpoint for an Azure Arc-enabled Kubernetes cluster. But that may not be such a tall order, says Breen, who notes that a number of free and commercial DNS discovery services now make it easy to find this information on potential targets.
Late last month, Microsoft acknowledged that attackers were exploiting two previously unknown vulnerabilities in Exchange Server. Paired together, the two flaws are known as “ProxyNotShell” and they can be chained to allow remote code execution on Exchange Server systems.
Microsoft said it was expediting work on official patches for the Exchange bugs, and it urged affected customers to enable certain settings to mitigate the threat from the attacks. However, those mitigation steps were soon shown to be ineffective, and Microsoft has been adjusting them on a daily basis nearly each day since then.
The lack of Exchange patches leaves a lot of Microsoft customers exposed. Security firm Rapid7 said that as of early September 2022 the company observed more than 190,000 potentially vulnerable instances of Exchange Server exposed to the Internet.
“While Microsoft confirmed the zero-days and issued guidance faster than they have in the past, there are still no patches nearly two weeks out from initial disclosure,” said Caitlin Condon, senior manager of vulnerability research at Rapid7. “Despite high hopes that today’s Patch Tuesday release would contain fixes for the vulnerabilities, Exchange Server is conspicuously missing from the initial list of October 2022 security updates. Microsoft’s recommended rule for blocking known attack patterns has been bypassed multiple times, emphasizing the necessity of a true fix.”
Adobe also released security updates to fix 29 vulnerabilities across a variety of products, including Acrobat and Reader, ColdFusion, Commerce and Magento. Adobe said it is not aware of active attacks against any of these flaws.
For a closer look at the patches released by Microsoft today and indexed by severity and other metrics, check out the always-useful Patch Tuesday roundup from the SANS Internet Storm Center. And it’s not a bad idea to hold off updating for a few days until Microsoft works out any kinks in the updates: AskWoody.com usually has the lowdown on any patches that may be causing problems for Windows users.
As always, please consider backing up your system or at least your important documents and data before applying system updates. And if you run into any problems with these updates, please drop a note about it here in the comments.
Text extracted automatically; images, tables and formatting may be missing. Original: https://krebsonsecurity.com/2022/10/microsoft-patch-tuesday-october-2022-edition/