ZeroHour
Security Affairspublished ()ingested @securityaffairs

December 2022 Patch Tuesday fixed 2 zero

criticalVulnerability exploited in the wildimportance 60CVE-2022-44698CVE-2022-44710

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-44698
SmartScreen Security Feature Bypass in Windows 10/11 and Windows Server

CVE-2022-44698 is a security feature bypass in Microsoft Defender SmartScreen in which specially crafted files do not properly trigger the SmartScreen Mark-of-the-Web warning prompt. The flaw is triggered over the network but requires user interaction: an attacker typically delivers a crafted file via a malicious link or phishing email, and when the user clicks or opens it, SmartScreen fails to show its usual warning. An attacker gains the ability to run malicious content on a user's machine without the standard SmartScreen prompt, making the flaw an effective delivery and initial-access aid — it has documented use in ransomware campaigns. Anyone running the affected Windows releases is exposed: Windows 10 versions 1607 through 22H2, Windows 11 21H2, and Windows Server 2016, 2019, and 2022. The vulnerability was exploited as a zero-day before patching, was added to CISA's Known Exploited Vulnerabilities catalog on 2022-12-13 with known ransomware use, and Google reported a ransomware gang abusing it in the wild.

Do: Apply Microsoft's December 2022 security updates (or any later cumulative updates) for Windows 10, Windows 11, and Windows Server, prioritizing user workstations and systems exposed to phishing or web downloads, per the CISA KEV required action. Until patched, reinforce user awareness that downloaded files may not trigger the usual SmartScreen warning, and consider restricting download or execution of risky file types. Confirm remediation against CISA KEV guidance and treat this as high-priority given known ransomware exploitation.

5.476% KEV ransomware
  • microsoft Windows 10 1607, 1809, 20H2, 21H1, 21H2, 22H2
  • microsoft Windows 11 21H2
  • microsoft Windows Server 2016, 2019, 2022
  • +1 more
masshundreds of millions of Windows endpoints (SmartScreen is built into every affected Windows 10/11 and Windows Server installation)
CVE-2022-44710
DirectX Graphics Kernel Elevation of Privilege Vulnerability

DirectX Graphics Kernel Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.8<1%
  • microsoft windows 11
Full article261 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 14, 2022

Microsoft released December 2022 Patch Tuesday security updates that fix 52 vulnerabilities across its products.

Microsoft December 2022 Patch Tuesday security updates addressed 52 vulnerabilities in Microsoft Windows and Windows Components; Azure; Office and Office Components; SysInternals; Microsoft Edge (Chromium-based); SharePoint Server; and the .NET framework. 12 of these vulnerabilities were submitted through the ZDI program.

Six vulnerabilities are rated Critical, 43 Important, and three are Moderate in severity. Microsoft December 2022 Patch Tuesday security updates fixed two zero-day vulnerabilities; one of the new issues addressed this month is listed as publicly known at the time of release, and one is actively exploited.

The actively exploited zero-day is a Windows SmartScreen security feature bypass vulnerability tracked as CVE-2022-44698.

“An attacker can craft a malicious file that would evade Mark of the Web (MOTW) defenses, resulting in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging.” reads the advisory published by the IT giant.

Another interesting flaw addressed by Microsoft is a DirectX Graphics Kernel elevation of privilege vulnerability tracked as CVE-2022-44710.

“An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.” reads the advisory. “Successful exploitation of this vulnerability requires an attacker to win a race condition.”

The full list of CVEs released by Microsoft for December 2022 is available here.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, December 2022 Patch Tuesday)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/139640/security/december-2022-patch-tuesday.html