ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-22947
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send

When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server.

NVD description · AI analysis pending
5.93% PoC
  • haxx curl
  • haxx fedora
  • haxx debian linux
  • +1 more
CVE-2021-36976
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).

libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).

NVD description · AI analysis pending
6.53%
  • libarchive libarchive
  • libarchive fedora
  • libarchive ipados
  • +1 more
CVE-2022-21874
+2 in the same advisory: …21836 …21839
Windows Security Center API Remote Code Execution Vulnerability

Windows Security Center API Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.8
group max
2%
  • microsoft windows 10
  • microsoft windows 11
  • microsoft windows server
  • +1 more
CVE-2022-21919
Local Privilege Escalation in Microsoft Windows User Profile Service

The Windows User Profile Service contains a link-following flaw (CWE-59) that lets an authenticated local attacker with low privileges elevate to SYSTEM/administrator rights, typically by planting a junction or symlink that the service follows while handling user profile operations. The attack is local-only (AV:L) with high attack complexity and no user interaction required, so it cannot be exploited remotely or by unauthenticated users. Any environment running the affected Windows releases — Windows 7, 8.1, RT 8.1, Windows 10 versions 1507 through 21H2, Windows 11 21H2, and Windows Server 2008 per the CPE data — is exposed wherever standard users can execute code. Microsoft shipped the fix in its January 2022 Patch Tuesday release, and CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2022-04-25, confirming exploitation in the wild. Ransomware association is not documented, and no public proof-of-concept is known; EPSS currently puts 30-day exploitation probability at 3.0% (86th percentile).

Do: Apply Microsoft's January 2022 Patch Tuesday security updates (or any later cumulative/LC updates) to all affected Windows 7/8.1/10/11 clients, Windows RT 8.1 devices, and Windows Server 2008 systems, per CISA's required action. Windows 7/8.1/Server 2008 may require Extended Security Updates where mainstream support has ended. Prioritize hosts that expose interactive logon to untrusted or low-privilege users and verify patch compliance, given the KEV listing confirms active exploitation.

7.03% KEV
  • Microsoft Windows 10 1507, 1607, 1809, 1909, 20H2, 21H1, 21H2
  • Microsoft Windows 11 21H2
  • Microsoft Windows 7 all editions in scope (no specific build range provided in source data)
  • +3 more
masshundreds of millions of Windows endpoints and servers (Windows 10/11 installed base is on the order of one billion devices; unpatched share unknown)
Full article300 words · extracted from infosecurity-magazine.com · click to collapse

Microsoft has been forced to issue an out-of-band update to fix several problems reported by system administrators following this month’s Patch Tuesday.

After installing the January Windows update, customers complained of Hyper-V not starting, Windows resilient file system (ReFS) being no longer accessible, unwanted system reboots and other issues.

Microsoft responded on Monday with a new update designed to fix the problems.

“This update addresses issues related to VPN connectivityWindows Server Domain Controllers restartingvirtual machines start failures and ReFS-formatted removable media failing to mount,” it noted.

“All updates are available on the Microsoft Update Catalog, and some are also available on Windows Update as an optional update. Check the release notes for your version of Windows for more information.”

Updates for Windows 8.1, Windows Server 2012 R2 and Windows Server 2012 are available only on the Microsoft Update Catalog. Updates for all other versions are available on Windows Update as an optional update.

Microsoft kicked off 2022 with fixes for 97 CVEs last week, including six publicly disclosed but not exploited.

Among these were CVE-2022-21839, a denial of service vulnerability in the Windows event tracing discretionary access control list; an elevation of privilege flaw in Windows user profile service (CVE-2022-21919); and a Windows certificates spoofing vulnerability (CVE-2022-21836).

The remaining three publicly disclosed flaws were remote code execution bugs in Windows Security Center API (CVE-2022-21874), libarchive (CVE-2021-36976) and open-source curl (CVE-2021-22947).

The Patch Tuesday release also included fixes for nine critical vulnerabilities, the largest number since July 2021.

Last year was a record-setter regarding new CVEs published to the US National Vulnerability Database.

By early December, the figure had reached 18,376, the fifth year in a row that it hit an all-time high.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-outofband-update-patch/