ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-22947
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send

When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server.

NVD description · AI analysis pending
5.93% PoC
  • haxx curl
  • haxx fedora
  • haxx debian linux
  • +1 more
CVE-2021-36976
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).

libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).

NVD description · AI analysis pending
6.53%
  • libarchive libarchive
  • libarchive fedora
  • libarchive ipados
  • +1 more
CVE-2022-21907
HTTP Protocol Stack Remote Code Execution Vulnerability

HTTP Protocol Stack Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.8
group max
93%
  • microsoft windows 10
  • microsoft windows 11
  • microsoft windows server
  • +1 more
CVE-2022-21840
Microsoft Office Remote Code Execution Vulnerability

Microsoft Office Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.83%
  • microsoft excel
  • microsoft office
  • microsoft office long term servicing channel
  • +1 more
CVE-2022-21969
+2 in the same advisory: …21846 …21855
Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.01%
  • microsoft exchange server
CVE-2022-21919
Local Privilege Escalation in Microsoft Windows User Profile Service

The Windows User Profile Service contains a link-following flaw (CWE-59) that lets an authenticated local attacker with low privileges elevate to SYSTEM/administrator rights, typically by planting a junction or symlink that the service follows while handling user profile operations. The attack is local-only (AV:L) with high attack complexity and no user interaction required, so it cannot be exploited remotely or by unauthenticated users. Any environment running the affected Windows releases — Windows 7, 8.1, RT 8.1, Windows 10 versions 1507 through 21H2, Windows 11 21H2, and Windows Server 2008 per the CPE data — is exposed wherever standard users can execute code. Microsoft shipped the fix in its January 2022 Patch Tuesday release, and CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2022-04-25, confirming exploitation in the wild. Ransomware association is not documented, and no public proof-of-concept is known; EPSS currently puts 30-day exploitation probability at 3.0% (86th percentile).

Do: Apply Microsoft's January 2022 Patch Tuesday security updates (or any later cumulative/LC updates) to all affected Windows 7/8.1/10/11 clients, Windows RT 8.1 devices, and Windows Server 2008 systems, per CISA's required action. Windows 7/8.1/Server 2008 may require Extended Security Updates where mainstream support has ended. Prioritize hosts that expose interactive logon to untrusted or low-privilege users and verify patch compliance, given the KEV listing confirms active exploitation.

7.03% KEV
  • Microsoft Windows 10 1507, 1607, 1809, 1909, 20H2, 21H1, 21H2
  • Microsoft Windows 11 21H2
  • Microsoft Windows 7 all editions in scope (no specific build range provided in source data)
  • +3 more
masshundreds of millions of Windows endpoints and servers (Windows 10/11 installed base is on the order of one billion devices; unpatched share unknown)
Full article694 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJan 12, 2022

Microsoft on Tuesday kicked off its first set of updates for 2022 by plugging 96 security holes across its software ecosystem, while urging customers to prioritize patching for what it calls a critical "wormable" vulnerability.

Of the 96 vulnerabilities, nine are rated Critical and 89 are rated Important in severity, with six zero-day publicly known at the time of the release. This is in addition to 29 issues patched in Microsoft Edge on January 6, 2022. None of the disclosed bugs are listed as under attack.

The patches cover a swath of the computing giant's portfolio, including Microsoft Windows and Windows Components, Exchange Server, Microsoft Office and Office Components, SharePoint Server, .NET Framework, Microsoft Dynamics, Open-Source Software, Windows Hyper-V, Windows Defender, and Windows Remote Desktop Protocol (RDP).

Chief among them is CVE-2022-21907 (CVSS score: 9.8), a remote code execution vulnerability rooted in the HTTP Protocol Stack. "In most situations, an unauthenticated attacker could send a specially crafted packet to a targeted server utilizing the HTTP Protocol Stack (http.sys) to process packets," Microsoft noted in its advisory.

Russian security researcher Mikhail Medvedev has been credited with discovering and reporting the error, with the Redmond-based company stressing that it's wormable, meaning no user interaction is necessary to trigger and propagate the infection.

"Although Microsoft has provided an official patch, this CVE is another reminder that software features allow opportunities for attackers to misuse functionalities for malicious acts," Danny Kim, principal architect at Virsec, said.

Microsoft also resolved six zero-days as part of its Patch Tuesday update, two of which are an integration of third-party fixes concerning the open-source libraries curl and libarchive.

  • CVE-2021-22947 (CVSS score: N/A) – Open-Source curl Remote Code Execution Vulnerability
  • CVE-2021-36976 (CVSS score: N/A) – Open-Source libarchive Remote Code Execution Vulnerability
  • CVE-2022-21836 (CVSS score: 7.8) – Windows Certificate Spoofing Vulnerability
  • CVE-2022-21839 (CVSS score: 6.1) – Windows Event Tracing Discretionary Access Control List Denial of Service Vulnerability
  • CVE-2022-21874 (CVSS score: 7.8) – Windows Security Center API Remote Code Execution Vulnerability
  • CVE-2022-21919 (CVSS score: 7.0) – Windows User Profile Service Elevation of Privilege Vulnerability

Another critical vulnerability of note concerns a remote code execution flaw (CVE-2022-21849, CVSS score: 9.8) in Windows Internet Key Exchange (IKE) version 2, which Microsoft said could be weaponized by a remote attacker to "trigger multiple vulnerabilities without being authenticated."

On top of that, the patch also remediates a number of remote code execution flaws affecting Exchange Server, Microsoft Office (CVE-2022-21840), SharePoint Server, RDP (CVE-2022-21893), and Windows Resilient File System as well as privilege escalation vulnerabilities in Active Directory Domain Services, Windows Accounts Control, Windows Cleanup Manager, and Windows Kerberos, among others.

It's worth stressing that CVE-2022-21907 and the three shortcomings uncovered in Exchange Server (CVE-2022-21846, CVE-2022-21855, and CVE-2022-21969, CVSS scores: 9.0) have all been labeled as "exploitation more likely," necessitating that the patches are applied immediately to counter potential real-world attacks targeting the weaknesses. The U.S. National Security Agency (NSA) has been acknowledged for flagging CVE-2022-21846.

"This massive Patch Tuesday comes during a time of chaos in the security industry whereby professionals are working overtime to remediate Log4Shell — reportedly the worst vulnerability seen in decades," Bharat Jogi, director of vulnerability and threat Research at Qualys, said.

"Events such as Log4Shell […] bring to the forefront the importance of having an automated inventory of everything that is used by an organization in their environment," Jogi added, stating "It is the need of the hour to automate deployment of patches for events with defined schedules (e.g., MSFT Patch Tuesday), so security professionals can focus energy to respond efficiently to unpredictable events that pose dastardly risk."

Software Patches from Other Vendors

Besides Microsoft, security updates have also been released by other vendors to rectify several vulnerabilities, counting —

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/01/first-patch-tuesday-of-2022-brings-fix.html