Microsoft October 2022 Patch Tuesday Fixes 84 Flaws, Including Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-41040 | Server-Side Request Forgery in Microsoft Exchange Server (ProxyNotShell) CVE-2022-41040 is a server-side request forgery (SSRF, CWE-918) vulnerability in Microsoft Exchange Server, publicly tracked under the name "ProxyNotShell" together with CVE-2022-41082. It is triggered when an attacker sends crafted HTTP requests to exposed Exchange web endpoints (such as Autodiscover), causing the server to issue attacker-influenced requests to itself. On its own the SSRF coerces authenticated server-side requests, but when chained with the CVE-2022-41082 remote code execution flaw it gives the attacker code execution on the Exchange server, typically followed by web shells, data access, and — in observed campaigns — ransomware deployment. Organizations running on-premises Microsoft Exchange Server are affected; the source data lists only Microsoft Exchange Server and does not specify affected version ranges, and hosted Exchange Online is a separate product not listed here. The vulnerability is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-30 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days; no public PoC is listed. Do: Apply Microsoft's Exchange Server security updates per vendor instructions immediately, as required by the CISA KEV catalog. As interim mitigation, restrict or block untrusted internet access to Exchange web endpoints (e.g., Autodiscover, OWA, ECP), and review IIS logs for suspicious crafted requests indicating SSRF or the chained CVE-2022-41082 exploitation. Given documented ransomware use, prioritize any internet-facing Exchange server and hunt for web shells and post-exploitation activity. | 8.8 | 100% | KEV ransomware PoC |
| mass≈250,000+ internet-exposed Exchange servers (public scans of exposed OWA/ECP/Exchange endpoints) |
Full article314 words · extracted from infosecurity-magazine.com · click to collapse
Microsoft published its October 2022 Patch Tuesday bulletin yesterday, which showcases fixes for an actively exploited Windows vulnerability alongside 83 other flaws.
Of the 84 vulnerabilities fixed in yesterday's update, 13 are classified as 'Critical' as they alternatively or jointly allow privilege elevation, spoofing or remote code execution. As for the others, 69 are rated Important, and one is rated Moderate.
Further, this month's Patch Tuesday fixed two zero-day vulnerabilities. The first zero-day is a Windows COM+ Event System Service elevation of privilege vulnerability (CVSS score: 7.8), which affects an unknown function of the component COM+ Event System Service.
"This patch fixes a security vulnerability that Microsoft stated is under active attack. However, it is not clear how severe these attacks are," commented Saeed Abbasi, manager of vulnerability signatures at Qualys.
"Due to the nature of this vulnerability, a privilege escalation that often engages some social engineering (e.g., requiring the user to open a malicious attachment), history shows that it potentially needs to be chained with a code execution bug to exploit."
The second zero-day, on the other hand, is a Microsoft Office Information Disclosure Vulnerability with a CVSS score of 3.3/10.
Notably, Microsoft has not included a patch to the ProxyNotShell vulnerability in Exchange Server (tracked CVE-2022-41040) after confirming its existence almost two weeks ago.
"It's worth noting that Microsoft has had to revise the mitigation for CVE-2022-41040 more than once, as the suggested URL rewrite Mitigation was bypassed multiple times," explained Ankit Malhotra, manager of signature engineering at Qualys.
"Organizations that reacted to the ProxyShell vulnerability should also pay close attention to this, taking their lessons learned on rapid remediation, as this vulnerability can potentially see increased exploitation."
Microsoft's October 2022 Patch Tuesday report comes roughly a month after Apple released an iOS 12 update for older iPhone and iPad devices to patch a vulnerability that threat actors reportedly exploited.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-october-patch-tuesday/