ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

September 2022 Patch Tuesday forecast: No sign of cooling off

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-32893
+1 in the same advisory: …32894
Out-of-Bounds Write in Apple WebKit (iOS/macOS/Safari) Enables RCE

CVE-2022-32893 is an out-of-bounds write flaw (CWE-787) in Apple's WebKit browser engine, caused by insufficient bounds checking. It is triggered when a device processes maliciously crafted web content, meaning a user can be attacked simply by loading an attacker-controlled webpage. A successful exploit allows arbitrary code execution on the victim's device, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). Affected users include anyone running iOS/iPadOS before 15.6.1, macOS Monterey before 12.5.1, or Safari before 15.6.1, as well as consumers of WebKitGTK and WPE WebKit shipped in Fedora and Debian. Apple confirmed the issue was being actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-18; EPSS estimates a 9.9% probability of exploitation in the next 30 days (95th percentile), while no public PoC is known.

Do: Immediately update to iOS 15.6.1, iPadOS 15.6.1, macOS Monterey 12.5.1, and Safari 15.6.1; per vendor reporting, Apple also released updates for older iPhone models, and users of devices running the iOS 15.7 beta should apply 15.6.1. Fedora and Debian users should install the patched WebKitGTK/WPE WebKit packages from their distribution's advisories. Because exploitation requires only loading malicious web content, there is no reliable workaround — prioritize patching on all endpoints that browse web content, and treat unpatched Apple devices as actively targeted.

8.8
group max
10% KEV
  • Apple iPhone OS (iOS) all versions prior to 15.6.1
  • Apple iPadOS all versions prior to 15.6.1
  • Apple macOS Monterey prior to 12.5.1
  • +5 more
masshundreds of millions of devices (Apple's active iPhone/Mac installed base plus Safari/WebKit users)
CVE-2022-34713
Remote Code Execution in Microsoft Windows Support Diagnostic Tool (MSDT) (DogWalk)

CVE-2022-34713, commonly referred to as 'DogWalk,' is a remote code execution vulnerability in the Microsoft Windows Support Diagnostic Tool (MSDT), patched in Microsoft's August 2022 Patch Tuesday release. The flaw requires user interaction: a user who engages with attacker-supplied content that invokes MSDT can allow the attacker's file operations to run in the context of the logged-on user, yielding high-impact code execution (confidentiality, integrity, and availability all rated high in the CVSS vector). Affected products span essentially the entire supported Windows installed base at the time: Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 21H2), Windows 11 21H2, and Windows Server 2008 and 2012. The vulnerability was confirmed by Microsoft as an actively exploited zero-day in August 2022 and was added to CISA's Known Exploited Vulnerabilities catalog on 2022-08-09, with a required action to apply vendor updates. EPSS assigns it a 67.8% probability of exploitation within 30 days (99th percentile), consistent with in-the-wild use.

Do: Apply the August 2022 (or later) Windows security updates on all affected Windows 7, 8.1, RT 8.1, 10 (1507–21H2), 11 21H2, Server 2008, and Server 2012 systems per vendor instructions, prioritizing user-facing workstations where exploitation depends on user interaction. Given the KEV listing, federal and high-value environments should verify patch status immediately and hunt for suspicious MSDT/diagnostic-tool invocations. No public PoC is known, but treat any unpatched system as exposed given confirmed in-the-wild exploitation.

7.868% KEV
  • microsoft Windows 10 1507, 1607, 1809, 20H2, 21H1, 21H2
  • microsoft Windows 11 21H2
  • microsoft Windows 7 all supported editions as listed (no SP range specified in source data)
  • +4 more
masshundreds of millions of devices
CVE-2022-38395
HP Support Assistant uses HP Performance Tune-up as a diagnostic tool.

HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to launch HP Performance Tune-up. It is possible for an attacker to exploit the DLL hijacking vulnerability and elevate privileges when Fusion launches the HP Performance Tune-up.

NVD description · AI analysis pending
7.83%
  • hp fusion
  • hp support assistant
Full article511 words · extracted from helpnetsecurity.com · click to collapse

September is here, and for most of us in the northern hemisphere, cooler temperatures are on the way. Unfortunately, the need to maintain and update our computer systems remains hot.

September 2022 Patch Tuesday forecast

August 2022 Patch Tuesday provided critical updates for all Microsoft operating systems as well as an unexpected update for Internet Explorer 11. These critical updates were driven by another zero-day vulnerability – CVE-2022-34713, found in the Microsoft Windows Support Diagnostic Tool (MSDT). There were also some zero-day vulnerabilities addressed by Apple this month, so let’s take a look before the forecast for next week.

Apple released security updates for all its operating systems – iOS, Catalina, Big Sur, and Monterey, as well as the Safari browser to address two zero-day vulnerabilities. CVE-2022-32893 and CVE-2022-32894 both are out-of-bounds write vulnerabilities that could allow code execution.

Google released a major update to its stable channel version of Chrome 105 for Windows, Mac, and Linux. It contained fixes for 24 vulnerabilities, including 9 that could allow for remote code execution. And of the final note, Hewlett-Packard released an update for its Support Assistant tool, which is installed on all its computer devices. It fixes CVE-2022-38395, an elevation of privilege vulnerability in this widespread, critical diagnostic software. All these products are in common use, so ensure you include these updates in your patch Tuesday process if you haven’t deployed them already.

Microsoft is disabling basic authentication for Exchange Online effective October 1st. This is the final action that began with the first announcement three years ago. The Microsoft Exchange Team blog provides an excellent summary of the timelines involved until the service is shut down permanently in January 2023. You can run the diagnostics tool and work with Microsoft to run a needed protocol until December. But be aware that using the basic authentication service is subject to man-in-the-middle compromise because the credentials are sent in plain text and rely on TLS and the end applications for protection. If you haven’t taken any action to update to modern authentication, your users may be blocked beginning at the end of September.

September 2022 Patch Tuesday forecast

  • Microsoft will continue to crank out the updates for Windows 11, Windows 10, and its older operating systems. Expect a continuing high number of CVEs fixed this month. We may see some .NET framework updates.
  • Adobe Acrobat and Reader were updated again in August following the major update in July. I wouldn’t expect another update this month.
  • Apple released security updates for its OS and Safari browser in mid-August, so I don’t expect another update soon.
  • Mozilla continues to release security updates for their applications at the end of the month so don’t expect any updates next week. Firefox 104, Firefox ESR 91.13, Firefox ESR 102.2, Thunderbird 91.13 and Thunderbird 102.2.1 were all updated so include them in your patch process next week.

The zero-day and other critical updates continue to surface, so our need to update systems remains as hot as ever. With these and more coming from Microsoft next week, make sure you have a cool drink nearby!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/09/09/september-2022-patch-tuesday-forecast/