CISA adds Windows bug to exploited list, urges agencies to patch by August 2
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-22047 | Local Privilege Escalation in Windows CSRSS Affects Nearly All Windows Versions CVE-2022-22047 is an elevation-of-privilege vulnerability in the Windows Client Server Run-time Subsystem (CSRSS), a core user-mode process that handles console and system tasks, caused by an untrusted search path (CWE-426). An attacker who already has a low-privileged foothold on a Windows machine can trigger the flaw locally, with no user interaction, to elevate to SYSTEM/administrator-level privileges. Because CSRSS is present on essentially every Windows installation, the affected population spans Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 21H2), Windows 11 21H2, and Windows Server 2008 and 2012, meaning virtually every Windows desktop, laptop, and server in active use is potentially affected. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on July 12, 2022 with an August 2 patch deadline for federal agencies, and EPSS assigns it an 18.8% probability of exploitation within 30 days (97th percentile). Do: Apply Microsoft's July 12, 2022 (Patch Tuesday) security updates immediately across all affected releases, including Windows 7, 8.1, RT 8.1, and Server 2008/2012, where fixes arrive through the same July update servicing; CISA's KEV deadline for federal agencies is August 2, 2022. Treat any host where a local attacker has executed code as potentially compromised to SYSTEM level, and hunt for post-exploitation activity. Keep monitoring vendor guidance, as recent reporting suggests some patched Windows attack surfaces may still be exploitable, so continue applying follow-on Windows updates as they ship. | 7.8 | 19% | KEV |
| mass≈1 billion+ Windows devices and servers (the affected list spans Windows 7 through Windows 11 and legacy server releases) |
Full article468 words · extracted from therecord.media · click to collapse
The Cybersecurity and Infrastructure Security Agency ordered all federal civilian agencies to patch a Windows vulnerability by August 2 after Microsoft said it had detected exploitation of the bug. The issue – tagged as CVE-2022-22047 – carries a vulnerability score (CVSS) of 7.8 and affects the Windows Client Server Runtime Subsystem (CSRSS) found in Windows 7, 8.1, 10, 11, and Windows Server 2008, 2012, 2016, 2019, and 2022. The zero-day was among the 84 bugs included in Microsoft’s Patch Tuesday release for July. When asked for comment for more information about the vulnerability’s exploitation, Microsoft told The Record it “had nothing more to add.” Nicole Hoffman, senior cyberthreat intelligence analyst at Digital Shadows, said that while there are reports of exploitation, a proof of concept has not yet been released. Canonic Security’s Alon Rosenblum added that an exploit for the bug would only work after the attacker already has the means to execute code as an unprivileged user. “Privilege elevation vulnerabilities are especially dangerous, as many attack scenarios rely on them as leverage to move from the initial infiltration stage to the lateral movement stage by acquiring credentials and access to network locations,” Rosenblum explained. Elevation of privilege flaws are valuable for attackers that have already gained access to a vulnerable system, and that have limited privileges through other means, including social engineering or exploitation of a separate vulnerability, Tenable senior staff research engineer Satnam Narang told The Record. “They could potentially gain administrative privileges by running a specially crafted application that exploits this flaw,” Narang said. CISA added the bug to its list of known exploited vulnerabilities this week after Microsoft publicized the issue. Dustin Childs of Trend Micro’s Zero Day Initiative said it “allows an attacker to execute code as SYSTEM, provided they can execute other code on the target.” “Bugs of this type are typically paired with a code execution bug, usually a specially crafted Office or Adobe document, to take over a system,” Childs said, noting that it was an example of why so many security experts were dismayed by Microsoft’s recent decision to roll back a popular change that blocked Visual Basic for Applications (VBA) macros by default in a variety of Office apps. Microsoft said its decision will be “temporary” but did not provide a timeline for when it will be restored. “These attacks often rely on macros, which is why so many were disheartened to hear Microsoft’s delay in blocking all Office macros by default,” Childs said.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-adds-windows-bug-to-exploited-list-urges-agencies-to-patch-by-august-2