ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Microsoft’s Final Patch Tuesday Fixes Follina Bug

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-30136
Windows Network File System Remote Code Execution Vulnerability

Windows Network File System Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.873%
  • microsoft windows server 2012
  • microsoft windows server 2016
  • microsoft windows server 2019
CVE-2022-30163
+1 in the same advisory: …30139
Windows Hyper-V Remote Code Execution Vulnerability

Windows Hyper-V Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.5
group max
2%
  • microsoft windows 10
  • microsoft windows 11
  • microsoft windows 7
  • +1 more
CVE-2022-30190
MSDT URL Protocol Remote Code Execution in Microsoft Windows (Follina)

CVE-2022-30190 (Follina) is a remote code execution flaw in the Microsoft Windows Support Diagnostic Tool (MSDT) when MSDT is invoked through its ms-msdt URL protocol by a calling application such as Microsoft Word. Attackers trigger it by luring a user into opening a malicious document — typically a Word/RTF file whose link or remotely linked template launches the ms-msdt: URI with attacker-supplied commands — and CVSS 3.1 rates it 7.8 with a local attack vector and required user interaction. A successful exploit runs arbitrary code with the privileges of the calling application, allowing the attacker to install programs, view, change or delete data, or create new accounts in the user's context. Per the CISA data, affected platforms are Windows 7, 8.1 and RT 8.1, Windows 10 versions 1507 through 21H2, Windows 11 21H2, and Windows Server 2008 and 2012 — essentially any Windows installation that ships MSDT, with Office/Word as the common delivery vector. Exploitation is confirmed in the wild: Microsoft acknowledged it as an exploited zero-day, CISA added it to the KEV on 2022-06-14 with known ransomware use, EPSS puts the 30-day exploitation probability at 99.2% (99th percentile), and contemporaneous reporting also tied its use to espionage actors including APT28.

Do: Apply Microsoft's security updates per vendor instructions (the fix shipped in the June 2022 Patch Tuesday releases for the affected Windows versions), as required by CISA's KEV. If patching must be delayed, follow Microsoft's documented mitigation to disable the MSDT URL protocol (remove or restrict the HKEY_CLASSES_ROOT\ms-msdt registry key) and enforce Office Protected View / block Word from fetching remote templates over the network. Hunt for exploitation by checking whether Office processes (WINWORD.exe) launch msdt.exe or sdiagnhost.exe, or whether ms-msdt: URIs are invoked unexpectedly.

7.899% KEV ransomware PoC
  • Microsoft Windows 10 1507, 1607, 1809, 20H2, 21H1, 21H2
  • Microsoft Windows 11 21H2
  • Microsoft Windows 7
  • +4 more
mass≈1 billion+ Windows devices (effectively the entire supported Windows installed base)
Full article387 words · extracted from infosecurity-magazine.com · click to collapse

Microsoft has issued its last regular patch update round before introducing a new automated patching service, fixing over 50 CVEs, including a dangerous zero-day bug known as “Follina.”

Also known by its official moniker, CVE-2022-30190, Follina is being exploited in the wild by state-backed actors and the operators behind Qakbot, which has links to ransomware groups. It’s a remote code execution (RCE) bug affecting the popular utility Windows Support Diagnostic Tool (MSDT).

Microsoft patched three other critical vulnerabilities this month.

CVE-2022-30136 is an RCE vulnerability in the Windows Network File System (NFS), impacting Windows Server 2012-2019. CVE-2022-30139 is an RCE bug in Microsoft’s Lightweight Directory Access Protocol (LDAP) affecting Windows 10 and 11 and Windows Server 2016-2022

Finally, CVE-2022-30163 is an RCE bug in Windows Hyper-V and should also be prioritized alongside the other two, according to Recorded Future senior security architect Allan Liska.

“According to Microsoft this is a complex vulnerability to exploit; however, successful exploitation would allow an attacker with access to a low-privileged guest Hyper-V instance to gain access to a Hyper-V host, giving them full access to the system,” he explained.

“This vulnerability impacts Windows 7 through 11 and Windows Server 2008 through 2016.”

Mark Lamb, CEO of security vendor HighGround, argued that firms have historically been slow to apply the fixes listed in Patch Tuesday unless the vulnerabilities behind them receive much publicity, like PrintNightmare and Log4Shell.

That’s partly because of the sheer volume of CVEs being published each week and the difficulty many organizations have in prioritizing them according to business risk. Last year saw another record number listed in NIST’s National Vulnerability Database.

“Companies should be diligent in approving and deploying patches on a weekly basis, if possible, because you don’t know what the next vulnerability is going to be and whether it could have been mitigated by consistent and diligent patching,” argued Lamb.

“It’s also something that IT teams need to get stricter on with their users – there is always friction with users not wanting to be interrupted during the day, but in my opinion, this is something IT teams should be unwilling to compromise on.”

From July, Microsoft will encourage users to switch to Windows Autopatch, a new managed service designed to streamline the product update process for Windows 10/11 Enterprise E3 users with automated patching.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsofts-final-patch-tuesday/