ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

April Records First Patch Tuesday of 2022 to Top 100 CVEs

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-24497
+1 in the same advisory: …24491
Windows Network File System Remote Code Execution Vulnerability

Windows Network File System Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.835%
  • microsoft windows 10
  • microsoft windows 11
  • microsoft windows 8.1
  • +1 more
CVE-2022-24521
+1 in the same advisory: …26904
Out-of-bounds Write Privilege Escalation in Microsoft Windows CLFS Driver

CVE-2022-24521 is an elevation-of-privilege flaw in the Windows Common Log File System (CLFS) driver, a kernel component, caused by an out-of-bounds write (CWE-787). A local attacker who already has limited privileges on an affected Windows machine can trigger the bug and gain elevated (SYSTEM/administrator) rights without any user interaction. Because the CLFS driver is part of the operating system, every user and service on an unpatched host is exposed to post-compromise escalation, which ransomware operators use to move from an initial foothold to full control. Affected products per the data include Windows 10 releases 1507, 1607, 1809, 1909, 20H2, 21H1, and 21H2, Windows 11 21H2, Windows 7, Windows 8.1, Windows RT 8.1, and Windows Server 2008. The flaw was patched in Microsoft's April 2022 Patch Tuesday, added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-13, and is known to be used in ransomware campaigns, with public reporting tying exploitation to Cuba ransomware activity.

Do: Apply the April 2022 Microsoft security updates (Patch Tuesday, released April 12, 2022) to all affected Windows 10/11, Windows 7/8.1/RT 8.1, and Windows Server 2008 systems immediately, per the CISA KEV required action; note that Windows 7/8.1/RT 8.1 and Server 2008 may require Extended Security Updates to receive the fix. Because this is a local privilege escalation, prioritize hosts reachable for initial access, review endpoint telemetry for suspicious limited-user-to-SYSTEM activity, and watch for indicators associated with Cuba ransomware campaigns exploiting this flaw.

7.8
group max
7% KEV ransomware
  • Microsoft Windows 10 1507, 1607, 1809, 1909, 20H2, 21H1, 21H2
  • Microsoft Windows 11 21H2
  • Microsoft Windows 7 all supported editions
  • +3 more
mass≈1 billion+ Windows devices (the CLFS driver ships in all supported Windows 10/11 and legacy client releases)
Full article319 words · extracted from infosecurity-magazine.com · click to collapse

Sysadmins will have a busy time ahead after Microsoft published fixes for over 100 CVEs this month, including two zero-day bugs.

April’s Patch Tuesday saw patches released for 119 vulnerabilities in total.

The two publicly disclosed prior to Tuesday were CVE-2022-24521, a bug in the Windows Common Log File System Driver (CLFS) reported by the NSA. Already exploited in the wild, the vulnerability has a CVSS score of 7.8 and could allow privilege escalation.

The CLFS has previous when it comes to vulnerabilities, according to Tyler Reguly, manager of security R&D at Tripwire.

“CLFS is a general purpose logging service that can be used by both user and kernel-mode software,” he explained.

“Patches have been released for CLFS monthly since September 2021 with only one exception – November 2021. From September 2021 until today, we have seen 18 vulnerabilities patched within CLFS.”

Also publicly disclosed was CVE-2022-26904, a bug in Windows User Profile Service that could lead to the elevation of privilege if successfully exploited.

“Microsoft has listed the attack complexity as high given that it relies on a race condition, however exploit code is already publicly available, including in the Metasploit framework,” said Reguly.

Elsewhere, Windows Network File System (NFS) remote code execution (RCE) vulnerabilities CVE-2022-24491 and CVE-2022-24497 are worth addressing, according to Kev Breen, director of cyber threat research at Immersive Labs.

“These could be the kind of vulnerabilities which appeal to ransomware operators as they provide the potential to expose critical data. It is also important for security teams to note that NFS Role is not a default configuration for Windows devices,” he explained.

Microsoft also released patches for an additional 26 CVEs in its Edge browser.

This will be one of the last Patch Tuesday update rounds for many customers after Microsoft last week announced “Autopatch,” a new managed service designed to streamline the product update process for Windows 10/11 Enterprise E3 users.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/april-records-first-patch-tuesday/