Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-37966 +1 in the same advisory: …37967 | Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability NVD description · AI analysis pending | 8.1 group max | 3% |
| — | ||
| CVE-2022-41039 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.1 group max | 1% |
| — | ||
| CVE-2022-41044 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.1 | 1% |
| — | ||
| CVE-2022-41125 | Local Privilege Escalation in Microsoft Windows CNG Key Isolation Service CVE-2022-41125 is an elevation of privilege vulnerability (an out-of-bounds write, CWE-787) in the Windows CNG Key Isolation Service. A local attacker who already has the ability to execute low-privileged code on a vulnerable Windows system can trigger the flaw without user interaction. Successful exploitation grants the attacker elevated (SYSTEM-level) privileges, giving high confidentiality, integrity and availability impact on the host. The flaw affects a broad range of Windows 10, Windows 11, Windows 8.1 and Windows Server versions, meaning nearly the entire mainstream Windows installed base is in scope. It is being actively exploited in the wild: it was added to the CISA Known Exploited Vulnerabilities catalog on 2022-11-08 and was one of six actively exploited zero-days fixed in Microsoft's November 2022 Patch Tuesday release. Do: Apply the November 2022 Windows security updates (or any later cumulative update) from Microsoft per the vendor's instructions, and prioritize this patch since the flaw is confirmed actively exploited. Inventory endpoints and servers running the affected Windows 10, 11, 8.1 and Server 2012/2016 versions and verify each has received the November 2022 or newer cumulative update. No public exploit details or mitigations are published, so patching is the primary remediation; treat any unpatched host as at elevated risk. | 7.8 group max | 3% | KEV |
| mass≈1 billion+ Windows installations (affected versions span the mainstream Windows 10/11 desktop and Windows Server installed base) | |
| CVE-2022-41080 | Microsoft Exchange Server Privilege Escalation Exploited in Ransomware Campaigns CVE-2022-41080 is an elevation-of-privilege flaw in Microsoft Exchange Server that stems from improper handling of requests to the server's Autodiscover component, allowing an attacker with any valid authenticated mailbox account to escalate privileges on the server. It is triggered by sending crafted authenticated HTTP requests to the Autodiscover endpoint, and it lets attackers bypass the URL-rewrite mitigations defenders had deployed against the earlier ProxyNotShell SSRF. When chained with the related PowerShell remote-code-execution bug CVE-2022-41082, privilege escalation becomes full remote code execution on the Exchange server. Any organization running on-premises Exchange Server with the Autodiscover component reachable — especially internet-exposed OWA/Autodiscover endpoints — is affected. The flaw is actively exploited: it was added to CISA's KEV catalog on 2023-01-10, is known to be used by ransomware operators, and has been tied to the Play ransomware gang, including the attack that took Rackspace's hosted Exchange environment offline. Do: Apply Microsoft Exchange Server security updates per vendor instructions (this CVE was fixed in Microsoft's November 2022 Exchange security updates — verify your servers are fully patched through the January 2023 rollups and that no Exchange builds predate the fix). Until patched, apply and verify the Autodiscover URL-rewrite/allow-list mitigation, knowing this flaw is a known bypass vector, and restrict Autodiscover/OWA exposure where feasible. Hunt for compromise in IIS logs for unusual requests to /autodiscover/autodiscover.json followed by PowerShell (CVE-2022-41082) activity, and treat any suspicious authenticated sessions as potential ransomware precursor activity. | 8.8 | 77% | KEV ransomware |
| large≈10,000–100,000 internet-exposed on-premises Exchange servers | |
| CVE-2022-41106 | Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability NVD description · AI analysis pending | 8.8 | 2% |
| — |
Full article669 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, November 8, 2022 13:22
Microsoft released its monthly security update on Tuesday, disclosing 62 vulnerabilities. Of these vulnerabilities, 8 are classified as “Critical” and the rest are classified as “Important.”
Three of the critical entries are remote code execution (RCE) vulnerabilities for Windows Point-to-Point Tunneling Protocol (PPTP).
An unauthenticated attacker can send a specially crafted request to an RAS (Remote Access Server), which may lead to remote code execution. Although according to Microsoft, these three vulnerabilities are less likely to be exploited, as the attacker must win a complex race condition. In August of 2022’s Patch Tuesday release, several vulnerabilities for Windows PPTP were also disclosed.
Another notable vulnerability in this release is CVE-2022-41118, a remote code execution vulnerability for both the JScript9 and Chakra scripting languages. While exploiting this vulnerability requires that the attacker win a race condition, Microsoft has determined that exploitation is more likely. Successful exploitation of CVE-2022-41118 requires that the attacker convince the victim to visit a malicious server share or website. This requirement can likely be met by phishing emails or another form of social engineering.
Two of the entries listed as critical are privilege escalation vulnerabilities in Windows Kerberos. Microsoft has determined that exploitation of both is more likely.
- CVE-2022-37966 Windows Kerberos RC4-HMAC Elevation of Privilege
- CVE-2022-37967 Windows Kerberos Elevation of Privilege Vulnerability
CVE-2022-37966 is a privilege escalation vulnerability in Windows Kerberos, where an unauthenticated attacker may be able to leverage vulnerabilities in RFC 4757 (Kerberos encryption type RC4-HMAC-MD5) and MS-PAC (Privilege Attribute Certificate Data Structure specification) to bypass constrained delegation security features in a Windows AD environment. The attack complexity has been labeled as “High.”
CVE-2022-37967 is another privilege escalation vulnerability in Windows Kerberos, where an authenticated attacker could leverage cryptographic protocol vulnerabilities in the Windows Kerberos AES-SHA1 cipher suite. If an attacker is successful in gaining control over the service that is allowed for delegation, they can modify Kerberos PAC to elevate their privileges. In contrast to CVE-2022-37966, the attack complexity is considered “Low.”
Also listed in this release is CVE-2022-38015, a Windows Hyper-V denial of service vulnerability. This affects Windows 10 and 11 hosts, as well as Windows Server 2016 and 2022. While the attack complexity is listed as “Low,” Microsoft considers successful exploitation as “Less Likely.”
Talos also found and released coverage of CVE-2022-41106. Our more detailed explanation can be found in the TALOS-2022-1591 Spotlight.
The last critical disclosure is CVE-2022-41080, a Microsoft Exchange Server elevation of privilege vulnerability, which has a low attack complexity and successful exploitation is considered “More Likely.” CVE-2022-41080 affects Microsoft Exchange Server versions listed below:
- Microsoft Exchange Server 2013 Cumulative Update 23
- Microsoft Exchange Server 2016 Cumulative Update 22
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 11
- Microsoft Exchange Server 2019 Cumulative Update 12
Talos would also like to highlight three “Important” vulnerabilities as Microsoft has listed them as being successfully exploited in the wild:
- CVE-2022-41091 - Windows Mark of the Web Security Feature Bypass Vulnerability
- CVE-2022-41073 - Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-41125 - Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
A complete list of all the vulnerabilities Microsoft disclosed this month is available on its update page.
In response to these vulnerability disclosures, Talos is releasing a new Snort rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Cisco Secure Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.
The rules included in this release that protect against the exploitation of many of these vulnerabilities are 60815-60816, 60818-60819, 60820-60821, 60822-60823, 60831-60832, 60833-60834. For Snort 3, the following rules are also available to protect against these vulnerabilities: 300309, 300310, 300311, 300312, 300315, 300316.
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-for-november-2022/