Microsoft Issues Patches for 121 Flaws, Including Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-21980 | Microsoft Exchange Server Elevation of Privilege Vulnerability Microsoft Exchange Server Elevation of Privilege Vulnerability NVD description · AI analysis pending | 8.0 group max | 2% |
| — | ||
| CVE-2022-30190 | MSDT URL Protocol Remote Code Execution in Microsoft Windows (Follina) CVE-2022-30190 (Follina) is a remote code execution flaw in the Microsoft Windows Support Diagnostic Tool (MSDT) when MSDT is invoked through its ms-msdt URL protocol by a calling application such as Microsoft Word. Attackers trigger it by luring a user into opening a malicious document — typically a Word/RTF file whose link or remotely linked template launches the ms-msdt: URI with attacker-supplied commands — and CVSS 3.1 rates it 7.8 with a local attack vector and required user interaction. A successful exploit runs arbitrary code with the privileges of the calling application, allowing the attacker to install programs, view, change or delete data, or create new accounts in the user's context. Per the CISA data, affected platforms are Windows 7, 8.1 and RT 8.1, Windows 10 versions 1507 through 21H2, Windows 11 21H2, and Windows Server 2008 and 2012 — essentially any Windows installation that ships MSDT, with Office/Word as the common delivery vector. Exploitation is confirmed in the wild: Microsoft acknowledged it as an exploited zero-day, CISA added it to the KEV on 2022-06-14 with known ransomware use, EPSS puts the 30-day exploitation probability at 99.2% (99th percentile), and contemporaneous reporting also tied its use to espionage actors including APT28. Do: Apply Microsoft's security updates per vendor instructions (the fix shipped in the June 2022 Patch Tuesday releases for the affected Windows versions), as required by CISA's KEV. If patching must be delayed, follow Microsoft's documented mitigation to disable the MSDT URL protocol (remove or restrict the HKEY_CLASSES_ROOT\ms-msdt registry key) and enforce Office Protected View / block Word from fetching remote templates over the network. Hunt for exploitation by checking whether Office processes (WINWORD.exe) launch msdt.exe or sdiagnhost.exe, or whether ms-msdt: URIs are invoked unexpectedly. | 7.8 | 99% | KEV ransomware PoC |
| mass≈1 billion+ Windows devices (effectively the entire supported Windows installed base) | |
| CVE-2022-34713 | Remote Code Execution in Microsoft Windows Support Diagnostic Tool (MSDT) (DogWalk) CVE-2022-34713, commonly referred to as 'DogWalk,' is a remote code execution vulnerability in the Microsoft Windows Support Diagnostic Tool (MSDT), patched in Microsoft's August 2022 Patch Tuesday release. The flaw requires user interaction: a user who engages with attacker-supplied content that invokes MSDT can allow the attacker's file operations to run in the context of the logged-on user, yielding high-impact code execution (confidentiality, integrity, and availability all rated high in the CVSS vector). Affected products span essentially the entire supported Windows installed base at the time: Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 21H2), Windows 11 21H2, and Windows Server 2008 and 2012. The vulnerability was confirmed by Microsoft as an actively exploited zero-day in August 2022 and was added to CISA's Known Exploited Vulnerabilities catalog on 2022-08-09, with a required action to apply vendor updates. EPSS assigns it a 67.8% probability of exploitation within 30 days (99th percentile), consistent with in-the-wild use. Do: Apply the August 2022 (or later) Windows security updates on all affected Windows 7, 8.1, RT 8.1, 10 (1507–21H2), 11 21H2, Server 2008, and Server 2012 systems per vendor instructions, prioritizing user-facing workstations where exploitation depends on user interaction. Given the KEV listing, federal and high-value environments should verify patch status immediately and hunt for suspicious MSDT/diagnostic-tool invocations. No public PoC is known, but treat any unpatched system as exposed given confirmed in-the-wild exploitation. | 7.8 | 68% | KEV |
| masshundreds of millions of devices | |
| CVE-2022-35743 | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability NVD description · AI analysis pending | 7.8 | 1% |
| — |
Full article608 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananAug 10, 2022
As many as 121 new security flaws were patched by Microsoft as part of its Patch Tuesday updates for the month of August, which also includes a fix for a Support Diagnostic Tool vulnerability that the company said is being actively exploited in the wild.
Of the 121 bugs, 17 are rated Critical, 102 are rated Important, one is rated Moderate, and one is rated Low in severity. Two of the issues have been listed as publicly known at the time of the release.
It's worth noting that the 121 security flaws are in addition to 25 shortcomings the tech giant addressed in its Chromium-based Edge browser late last month and the previous week.
Topping the list of patches is CVE-2022-34713 (CVSS score: 7.8), a case of remote code execution affecting the Microsoft Windows Support Diagnostic Tool (MSDT), making it the second flaw in the same component after Follina (CVE-2022-30190) to be weaponized in real-world attacks within three months.
The vulnerability is also said to be a variant of the flaw publicly known as DogWalk, which was originally disclosed by security researcher Imre Rad in January 2020.
"Exploitation of the vulnerability requires that a user open a specially crafted file," Microsoft said in an advisory. "In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file."
Alternatively, an attacker could host a website or leverage an already compromised site that contains a malware-laced file designed to exploit the vulnerability, and then trick potential targets into clicking on a link in an email or an instant message to open the document.
"This is not an uncommon vector and malicious documents and links are still used by attackers to great effect," Kev Breen, director of cyber threat research at Immersive Labs, said. "It underscores the need for upskilling employees to be wary of such attacks."
CVE-2022-34713 is one of the two remote code execution flaws in MSDT closed by Redmond this month, the other being CVE-2022-35743 (CVSS score: 7.8). Security researchers Bill Demirkapi and Matt Graeber have been credited with reporting the vulnerability.
Microsoft also resolved three privilege escalation flaws in Exchange Server that could be abused to read targeted email messages and download attachments (CVE-2022-21980, CVE-2022-24477, and CVE-2022-24516) and one publicly-known information disclosure vulnerability (CVE-2022-30134) in Exchange which could as well lead to the same impact.
"Administrators should enable Extended Protection in order to fully remediate this vulnerability," Greg Wiseman, product manager at Rapid7, commented about CVE-2022-30134.
The security update further remediates multiple remote code execution flaws in Windows Point-to-Point Protocol (PPP), Windows Secure Socket Tunneling Protocol (SSTP), Azure RTOS GUIX Studio, Microsoft Office, and Windows Hyper-V.
The Patch Tuesday fix is also notable for addressing dozens of privilege escalation flaws: 31 in Azure Site Recovery, a month after Microsoft squashed 30 similar bugs in the business continuity service, five in Storage Spaces Direct, three in Windows Kernel, and two in the Print Spooler module.
Software Patches from Other Vendors
Aside from Microsoft, security updates have also been released by other vendors since the start of the month to rectify several vulnerabilities, including —
- Adobe
- AMD
- Android
- Apache Projects
- Cisco
- Citrix
- Dell
- F5
- Fortinet
- GitLab
- Google Chrome
- HP
- IBM
- Intel
- Linux distributions Debian, Oracle Linux, Red Hat, SUSE, and Ubuntu
- MediaTek
- NVIDIA
- Palo Alto Networks
- Qualcomm
- Samba
- SAP
- Schneider Electric
- Siemens, and
- VMware
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/08/microsoft-issues-patches-for-121-flaws.html