ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Surge in CVEs as Microsoft Fixes Exploited Zero Day Bugs

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-30133
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability

Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.83%
  • microsoft windows 10
  • microsoft windows 11
  • microsoft windows 7
  • +1 more
CVE-2022-30134
Microsoft Exchange Server Information Disclosure Vulnerability

Microsoft Exchange Server Information Disclosure Vulnerability

NVD description · AI analysis pending
6.52%
  • microsoft exchange server
CVE-2022-34713
Remote Code Execution in Microsoft Windows Support Diagnostic Tool (MSDT) (DogWalk)

CVE-2022-34713, commonly referred to as 'DogWalk,' is a remote code execution vulnerability in the Microsoft Windows Support Diagnostic Tool (MSDT), patched in Microsoft's August 2022 Patch Tuesday release. The flaw requires user interaction: a user who engages with attacker-supplied content that invokes MSDT can allow the attacker's file operations to run in the context of the logged-on user, yielding high-impact code execution (confidentiality, integrity, and availability all rated high in the CVSS vector). Affected products span essentially the entire supported Windows installed base at the time: Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 21H2), Windows 11 21H2, and Windows Server 2008 and 2012. The vulnerability was confirmed by Microsoft as an actively exploited zero-day in August 2022 and was added to CISA's Known Exploited Vulnerabilities catalog on 2022-08-09, with a required action to apply vendor updates. EPSS assigns it a 67.8% probability of exploitation within 30 days (99th percentile), consistent with in-the-wild use.

Do: Apply the August 2022 (or later) Windows security updates on all affected Windows 7, 8.1, RT 8.1, 10 (1507–21H2), 11 21H2, Server 2008, and Server 2012 systems per vendor instructions, prioritizing user-facing workstations where exploitation depends on user interaction. Given the KEV listing, federal and high-value environments should verify patch status immediately and hunt for suspicious MSDT/diagnostic-tool invocations. No public PoC is known, but treat any unpatched system as exposed given confirmed in-the-wild exploitation.

7.868% KEV
  • microsoft Windows 10 1507, 1607, 1809, 20H2, 21H1, 21H2
  • microsoft Windows 11 21H2
  • microsoft Windows 7 all supported editions as listed (no SP range specified in source data)
  • +4 more
masshundreds of millions of devices
CVE-2022-35744
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability

Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.82%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
Full article357 words · extracted from infosecurity-magazine.com · click to collapse

Microsoft addressed 121 vulnerabilities in the August 2022 Patch Tuesday update round, including two zero-day bugs.

One of the zero-days, CVE-2022-34713, has been dubbed “DogWalk” and is a remote code execution bug in the Microsoft Windows Support Diagnostic Tool (MSDT) which has already been observed in attacks in the wild.

“This is a user targeted vulnerability meaning the attacker can target the user with a variety of social engineering tactics such as sending a specially crafted file via email or convincing the user to click on hosted web content specially crafted to exploit the vulnerability,” explained Chris Goettl, Ivanti VP of product management.

“The vulnerability affects all Windows OS versions and is rated as ‘important’ by Microsoft. Due to the public disclosure and known attacks targeting the vulnerability, it is recommended to treat this as a higher priority.”

Qualys director of vulnerability and threat research, Bharat Jogi, said DogWalk had actually been reported back in 2019 but at the time was not thought to be dangerous as it required “significant user interaction to exploit,” and there were other mitigations in place.

However, the appearance of the novel Follina zero day, which also exploits MSDT, forced Microsoft to reconsider, he said.

The second zero-day (CVE-2022-30134) is an information disclosure vulnerability in Exchange Server that is regarded as less serious because the public disclosure doesn’t provide functional exploit code. Microsoft has provided more details on how to fix it here.

Aside from these two flaws, Microsoft fixed 17 critical CVEs, a 325% increase on July's figures.

These include two RCE bugs in the Windows Point-to-Point Tunneling Protocol which have a CVSS score of 9.8: CVE-2022-30133 and CVE-2022-35744.

“These vulnerabilities enable a network attack that does not require any action from the user. The attack is exploited on port 1723, causing remote execution of malicious code,” explained Action1 co-founder, Mike Walters.

“If you have a Windows Server-based remote access server (RAS) tunnel running on this port, you should change it to a less popular port. But be careful or it will cause your tunnels to fail to connect properly. Do it wisely on both sides."

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/surge-cves-microsoft-fixes/