iTnews Asia
  • Home
  • News
  • Security

Microsoft ships 68 patches, including 10 rated critical

Microsoft ships 68 patches, including 10 rated critical

One critical bug under active exploitation.

By Richard Chirgwin on Nov 9, 2022 11:51AM

Microsoft’s monthly shipment of patches covers 68 vulnerabilities, 10 of which are rated as critical.

Of the critical vulnerabilities, the SANS Institute said one is under active exploitation: CVE-2022-41128, a remote code execution (RCE) bug in the Windows Scripting Language.

The SANS institute describes it as impacting the JScript9 language.

The attacker would have to persuade a victim to visit a crafted website (probably in some kind of phishing attack): “It would not be hard for an attacker to accomplish this kind of interaction which makes this vulnerability worthy of special attention", the institute’s Patch Wednesday post states.

There are three critical RCEs patched in the Windows point-to-point tunneling protocol (CVE-2022-41039, CVE-2022-41044 and CVE-2022-41088).

There is also an Exchange Server privilege escalation (CVE-2022-41080), two escalation of privilege vulnerabilities in Windows Kerberos (CVE-2022-37966 and CVE-2022-37967), a denial-of-service vulnerability in Windows Hyper-V (CVE-2022-38015), and a code injection vulnerability in the Azure command line interface (CVE-2022-39327).

In addition to the Windows scripting vulnerability, three other patches were for bugs under exploitation, but none of them reached a critical rating.

They are: a privilege escalation in the Windows CNG key isolation service (CVE-2022-41125); a privilege escalation in the print spooler (CVE-2022-41073); and a Windows Mark of the Web bug (CVE-2022-41091).

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
microsoft patch tuesday security

Related Articles

  • Your organisation’s physical security can be a gateway for cybercriminals
  • The best way to outsmart your threat actors is to think like one
  • How cybercriminals are exploiting LLMs to harm your business
  • Is identity now the next parameter of cybersecurity breaches?
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

The best way to outsmart your threat actors is to think like one

The best way to outsmart your threat actors is to think like one

Your organisation’s physical security can be a gateway for cybercriminals

Your organisation’s physical security can be a gateway for cybercriminals

What are the most pressing cyber security concerns going into 2025?

What are the most pressing cyber security concerns going into 2025?

Malaysia ramps up cyber security defense to stem rising fraud and ransomware attacks

Malaysia ramps up cyber security defense to stem rising fraud and ransomware attacks

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.