Microsoft patches Windows flaw exploited in the wild (CVE-2022-41033)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-37968 | Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kubernetes cluster. Additionally, because Azure Stack Edge allows customers to deploy Kubernetes workloads on their devices via Azure Arc, Azure Stack Edge devices are also vulnerable to this vulnerability. NVD description · AI analysis pending | 10.0 | 3% |
| — | ||
| CVE-2022-38048 | Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability NVD description · AI analysis pending | 7.8 | 2% |
| — | ||
| CVE-2022-38053 | Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.8 | 76% |
| — | ||
| CVE-2022-41033 | Local Privilege Escalation in Microsoft Windows COM+ Event System Service CVE-2022-41033 is an elevation-of-privilege flaw in the Microsoft Windows COM+ Event System Service, classified under CWE-843 (access of a resource using an incompatible type). It is triggered locally: an attacker who can already execute code on a machine with limited (low-privilege) rights can exploit the vulnerable service with no user interaction, per the CVSS vector (AV:L/AC:L/PR:L/UI:N). Successful exploitation elevates the attacker to the highest local privilege level, with high impact on the confidentiality, integrity, and availability of the system — a typical post-compromise privilege-escalation step for an attacker who already has a foothold. The flaw affects the Windows releases in the CISA CPE data — Windows 7, 8.1, RT 8.1, Windows 10 (1507, 1607, 1809, 20H2, 21H1, 21H2), Windows 11 (21H2, 22H2), and Windows Server 2008 — meaning effectively the broad Windows installed base. Microsoft patched it in the October 2022 Patch Tuesday release and it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-11 as exploited in the wild; no public PoC is known, ransomware use is unknown, and EPSS currently estimates a 1.7% probability of exploitation in the next 30 days (75th percentile). Do: Apply the October 2022 Windows security updates (or any later cumulative update) on all affected Windows clients and servers, prioritizing hosts where low-privileged users can run code, such as workstations, terminal/RDS servers, and VDI images — this also satisfies the CISA KEV required action. Until patched, treat any unprivileged compromise of a Windows host as potentially escalated to full local privilege, and restrict untrusted local code execution where possible. Verify remediation by confirming the October 2022 (or newer) cumulative update level on each host rather than relying on OS version alone. | 7.8 | 2% | KEV |
| masson the order of 1 billion Windows devices (essentially the entire supported Windows client and server installed base) | |
| CVE-2022-41038 | Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.8 | 3% |
| — | ||
| CVE-2022-41040 +1 in the same advisory: …41082 | Server-Side Request Forgery in Microsoft Exchange Server (ProxyNotShell) CVE-2022-41040 is a server-side request forgery (SSRF, CWE-918) vulnerability in Microsoft Exchange Server, publicly tracked under the name "ProxyNotShell" together with CVE-2022-41082. It is triggered when an attacker sends crafted HTTP requests to exposed Exchange web endpoints (such as Autodiscover), causing the server to issue attacker-influenced requests to itself. On its own the SSRF coerces authenticated server-side requests, but when chained with the CVE-2022-41082 remote code execution flaw it gives the attacker code execution on the Exchange server, typically followed by web shells, data access, and — in observed campaigns — ransomware deployment. Organizations running on-premises Microsoft Exchange Server are affected; the source data lists only Microsoft Exchange Server and does not specify affected version ranges, and hosted Exchange Online is a separate product not listed here. The vulnerability is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-30 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days; no public PoC is listed. Do: Apply Microsoft's Exchange Server security updates per vendor instructions immediately, as required by the CISA KEV catalog. As interim mitigation, restrict or block untrusted internet access to Exchange web endpoints (e.g., Autodiscover, OWA, ECP), and review IIS logs for suspicious crafted requests indicating SSRF or the chained CVE-2022-41082 exploitation. Given documented ransomware use, prioritize any internet-facing Exchange server and hunt for web shells and post-exploitation activity. | 8.8 group max | 100% | KEV ransomware PoC |
| mass≈250,000+ internet-exposed Exchange servers (public scans of exposed OWA/ECP/Exchange endpoints) |
Full article548 words · extracted from helpnetsecurity.com · click to collapse
October 2022 Patch Tuesday is here, with fixes for 85 CVE-numbered vulnerabilities, including CVE-2022-41033, a vulnerability in Windows COM+ Event System Service that has been found being exploited in the wild.

But, first and foremost, it should be noted that the two MS Exchange zero-days under active exploitation (CVE-2022-41040 and CVE-2022-41082, aka ProxyNotShell) have still not been patched, and administrators must make do with Microsoft’s guidance on how to mitigate them until the fixes are ready.
About CVE-2022-41033
CVE-2022-41033 is an elevation of privilege (EoP) vulnerability in the Windows COM+ Event System Service, which automatically distributs events to Component Object Model (COM) components.
Microsoft’s advisory does not offer provide information on how the vulnerability is being exploited or if it is being exploited in targeted or more widespread attacks. They only say that the attack complexity is low and that it requires no user interaction for the attacker to be able to achieve SYSTEM privileges.
“All versions of Windows starting with Windows 7 and Windows Server 2008 are vulnerable. The Windows COM+ Event System Service is launched by default with the operating system and is responsible for providing notifications about logons and logoffs,” says Mike Walters, VP of Vulnerability and Threat Research at Action1.
“Installing the newly released patch is mandatory; otherwise, an attacker who is logged on to a guest or ordinary user computer can quickly gain SYSTEM privileges on that system and be able to do almost anything with it. This vulnerability is especially significant for organizations whose infrastructure relies on Windows Server.”
Other vulnerabilities to prioritize
CVE-2022-37968 has received the highest CVSS rating (10.0), meaning that it’s as critical as it can be. It’s another EoP flaw, but this one could allow an attacker to gain control over Azure Arc-enabled Kubernetes clusters.
“Azure Stack Edge devices may also be impacted by this bug. To exploit this remotely, the attacker would need to know the randomly generated DNS endpoint for an Azure Arc-enabled Kubernetes cluster,” noted Dustin Childs, with Trend Micro’s Zero Day Initiative.
“If you’re running these types of containers, make sure you either have auto-upgrade enabled or manually update to the latest version by running the appropriate commands in the Azure CLI.”
Childs also considers CVE-2022-38048, a Microsoft Office RCE flaw, a contender for quick patching. Microsoft rarely considers Office flaws critical, but in this case it does – even if user interaction is required for it to be triggered.
“Likely the rating results from the lack of warning dialogs when opening a specially crafted file. Either way, this is a UAF that could lead to passing an arbitrary pointer to a free call which makes further memory corruption possible,” he said.
Microsoft has also fixed seven critical vulnerabilities in the Point-to-Point Tunneling Protocol (PPTP), which is an outdated (and generally insecure) method for implementing VPNs. If you use it, you should implement the patches, but this might be a good time to consider a replacement.
Finally, Microsoft SharePoint users should check if they need to implement fixes for any of the four remote code execution flaws (CVE-2022-41036, CVE-2022-41037, CVE-2022-38053 and https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41038) fixed by Microsoft on this Patch Tuesday. While none of them are publicly disclosed, SharePoint is among attackers’ favorite targets, so quick patching is advised.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/10/11/cve-2022-41033/