ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Microsoft Patch Tuesday Fixes New Windows Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-37968
Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters.

Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kubernetes cluster. Additionally, because Azure Stack Edge allows customers to deploy Kubernetes workloads on their devices via Azure Arc, Azure Stack Edge devices are also vulnerable to this vulnerability.

NVD description · AI analysis pending
10.03%
  • microsoft azure arc-enabled kubernetes
  • microsoft azure stack edge
CVE-2022-37976
Active Directory Certificate Services Elevation of Privilege Vulnerability

Active Directory Certificate Services Elevation of Privilege Vulnerability

NVD description · AI analysis pending
8.82%
  • microsoft windows server 2008
  • microsoft windows server 2012
  • microsoft windows server 2016
  • +1 more
CVE-2022-38034
+2 in the same advisory: …38045 …37979
Windows Workstation Service Elevation of Privilege Vulnerability

Windows Workstation Service Elevation of Privilege Vulnerability

NVD description · AI analysis pending
8.8
group max
3%
  • microsoft windows 10
  • microsoft windows 11
  • microsoft windows 7
  • +1 more
CVE-2022-38028
Local Privilege Escalation in Microsoft Windows Print Spooler (CVE-2022-38028)

CVE-2022-38028 is an elevation-of-privilege vulnerability (CVSS 3.1: 7.8) in the Microsoft Windows Print Spooler, the service that manages print jobs on Windows machines. An attacker who can already run low-privileged code on a vulnerable system can exploit the flaw locally, with no user interaction required, to escalate to SYSTEM privileges and take full control of the host (high confidentiality, integrity, and availability impact). It affects a broad set of Windows releases — Windows 10 builds 1507 through 21H2, Windows 11 22H2, Windows 8.1 and Windows RT 8.1, and Windows Server 2012, 2016, and 2019 — so most unpatched Windows estates are in scope. Exploitation is confirmed in the wild: CISA added the bug to the KEV catalog on 2024-04-23 (ransomware use unknown), and public reporting attributes active use to the Russia-linked APT28 group, whose custom 'GooseEgg' tool leverages this NSA-reported flaw to run payloads with elevated privileges; Microsoft shipped the fix in its April 2024 Patch Tuesday. EPSS is 14.9% (96th percentile), indicating elevated near-term exploitation risk on top of the already-observed APT28 activity.

Do: Apply Microsoft's security updates for the affected Windows releases (fixed in the April 2024 Patch Tuesday); as a KEV entry, CISA requires applying vendor mitigations or discontinuing use of unpatched versions. On servers where printing is not required, disabling the Print Spooler service removes the local attack path. Given confirmed APT28 use of the 'GooseEgg' exploit, hunt for related activity on unpatched hosts and prioritize patching endpoints belonging to organizations and users targeted by APT28.

7.815% KEV
  • Microsoft Windows 10 1507, 1607, 1809, 20H2, 21H1, 21H2
  • Microsoft Windows 11 22H2
  • Microsoft Windows 8.1 all supported builds
  • +4 more
masshundreds of millions of Windows 10/11 endpoints plus millions of Windows Server hosts (every unpatched install of the listed releases)
CVE-2022-41033
Local Privilege Escalation in Microsoft Windows COM+ Event System Service

CVE-2022-41033 is an elevation-of-privilege flaw in the Microsoft Windows COM+ Event System Service, classified under CWE-843 (access of a resource using an incompatible type). It is triggered locally: an attacker who can already execute code on a machine with limited (low-privilege) rights can exploit the vulnerable service with no user interaction, per the CVSS vector (AV:L/AC:L/PR:L/UI:N). Successful exploitation elevates the attacker to the highest local privilege level, with high impact on the confidentiality, integrity, and availability of the system — a typical post-compromise privilege-escalation step for an attacker who already has a foothold. The flaw affects the Windows releases in the CISA CPE data — Windows 7, 8.1, RT 8.1, Windows 10 (1507, 1607, 1809, 20H2, 21H1, 21H2), Windows 11 (21H2, 22H2), and Windows Server 2008 — meaning effectively the broad Windows installed base. Microsoft patched it in the October 2022 Patch Tuesday release and it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-11 as exploited in the wild; no public PoC is known, ransomware use is unknown, and EPSS currently estimates a 1.7% probability of exploitation in the next 30 days (75th percentile).

Do: Apply the October 2022 Windows security updates (or any later cumulative update) on all affected Windows clients and servers, prioritizing hosts where low-privileged users can run code, such as workstations, terminal/RDS servers, and VDI images — this also satisfies the CISA KEV required action. Until patched, treat any unprivileged compromise of a Windows host as potentially escalated to full local privilege, and restrict untrusted local code execution where possible. Verify remediation by confirming the October 2022 (or newer) cumulative update level on each host rather than relying on OS version alone.

7.82% KEV
  • microsoft Windows 10 1507, 1607, 1809, 20H2, 21H1, 21H2 (CPE-listed releases)
  • microsoft Windows 11 21H2, 22H2 (CPE-listed releases)
  • microsoft Windows 7
  • +3 more
masson the order of 1 billion Windows devices (essentially the entire supported Windows client and server installed base)
CVE-2022-41043
Microsoft Office Information Disclosure Vulnerability

Microsoft Office Information Disclosure Vulnerability

NVD description · AI analysis pending
3.3<1%
  • microsoft office
  • microsoft office long term servicing channel
Full article540 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananOct 12, 2022

Microsoft's Patch Tuesday update for the month of October has addressed a total of 85 security vulnerabilities, including fixes for an actively exploited zero-day flaw in the wild.

Of the 85 bugs, 15 are rated Critical, 69 are rated Important, and one is rated Moderate in severity. The update, however, does not include mitigations for the actively exploited ProxyNotShell flaws in Exchange Server.

The patches come alongside updates to resolve 12 other flaws in the Chromium-based Edge browser that have been released since the beginning of the month.

Topping the list of this month's patches is CVE-2022-41033 (CVSS score: 7.8), a privilege escalation vulnerability in Windows COM+ Event System Service. An anonymous researcher has been credited with reporting the issue.

"An attacker who successfully exploited this vulnerability could gain SYSTEM privileges," the company said in an advisory, cautioning that the shortcoming is being actively weaponized in real-world attacks.

The nature of the flaw also means that the issue is likely chained with other flaws to escalate privilege and carry out malicious actions on the infected host.

"This specific vulnerability is a local privilege escalation, which means that an attacker would already need to have code execution on a host to use this exploit," Kev Breen, director of cyber threat research at Immersive Labs, said.

Three other elevation of privilege vulnerabilities of note relate to Windows Hyper-V (CVE-2022-37979, CVSS score: 7.8), Active Directory Certificate Services (CVE-2022-37976, CVSS score: 8.8), and Azure Arc-enabled Kubernetes cluster Connect (CVE-2022-37968, CVSS score: 10.0).

Despite the "Exploitation Less Likely" tag for CVE-2022-37968, Microsoft noted that a successful exploitation of the flaw could permit an "unauthenticated user to elevate their privileges as cluster admins and potentially gain control over the Kubernetes cluster."

Elsewhere, CVE-2022-41043 (CVSS score: 3.3) – an information disclosure vulnerability in Microsoft Office – is listed as publicly known at the time of release. It could be exploited to leak user tokens and other potentially sensitive information, Microsoft said.

Also fixed by Redmond are eight privilege escalation flaws in Windows Kernel, 11 remote code execution bugs in Windows Point-to-Point Tunneling Protocol and SharePoint Server, and yet another elevation of privilege vulnerability in the Print Spooler module (CVE-2022-38028, CVSS score: 7.8).

Lastly, the Patch Tuesday update further addresses two more privilege escalation flaws in Windows Workstation Service (CVE-2022-38034, CVSS score: 4.3) and Server Service Remote Protocol (CVE-2022-38045, CVSS score: 8.8).

Web security company Akamai, which discovered the two shortcomings, said they "take advantage of a design flaw that allows the bypass of [Microsoft Remote Procedure Call] security callbacks through caching."

Software Patches from Other Vendors

In addition to Microsoft, security updates have also been released by several vendors to rectify dozens of vulnerabilities, including —

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/10/microsoft-patch-tuesday-fixes-new.html