iTnews Asia
  • Home
  • News
  • Security

Seven critical vulnerabilities round out Microsoft's 2022

Seven critical vulnerabilities round out Microsoft's 2022

Plus one older patch upgraded to critical.

By Richard Chirgwin on Dec 14, 2022 10:34AM

Microsoft’s monthly patch drop covers 74 vulnerabilities, including seven that are rated critical and one lower-rated bug that has exploits in the wild.

The company has also upgraded a previously-disclosed vulnerability to critical after an IBM researcher demonstrated an exploit for it.

The critical vulnerabilities in the Patch Wednesday release include a .NET remote code execution (RCE) vulnerability, CVE-2022-41089, for which little detail is offered.

SharePoint Server has been patched for two critical vulnerabilities: CVE-2022-44690, which allows an authenticated attacker to execute code remotely if they have Manage List permissions, and CVE-2022-44693.

There’s also an RCE in PowerShell, CVE-2022-41076.

Microsoft’s advisory stated that while any authenticated user can exploit the bug, it “requires an attacker to take additional actions prior to exploitation to prepare the target environment."

“An authenticated attacker could escape the PowerShell Remoting Session Configuration and run unapproved commands on the target system.”

The other critical vulnerabilities are CVE-2022-41127, which affects Dynamics NAV and Dynamics 365 Business Central (on-premises); and two RCEs in the Windows Secure Socket Tunnelling Protocol, CVE-2022-44676 and CVE-2022-44670.

Old vulnerability re-rated

Microsoft has also upgraded a vulnerability first divulged in September to a critical rating.

CVE-2022-37958 is an RCE in the SPNEGO Extended Negotiation (NEGOEX) security mechanism.

IBM X-Force security researcher Valentina Palmiotti posted an exploit demonstration on 
Twitter, saying the vulnerability is “reachable via any Windows application protocol that authenticates. Yes, that means RDP, SMB and many more.”

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
microsoft patch rce security software

Related Articles

  • How making identity a priority can help bring clarity to AI chaos
  • Five tips a CIO or CSO should know to stop employee-driven IP theft
  • StarHub launches app to protect customers from scam calls and SMS
  • Beware the rise of ‘vishing’ as a cyber threat in APAC
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Five tips a CIO or CSO should know to stop employee-driven IP theft

Five tips a CIO or CSO should know to stop employee-driven IP theft

How can we bolster our resilience against AI-enabled e-mail attacks?

How can we bolster our resilience against AI-enabled e-mail attacks?

The real-life Tom & Jerry chase

The real-life Tom & Jerry chase

Beware the rise of ‘vishing’ as a cyber threat in APAC

Beware the rise of ‘vishing’ as a cyber threat in APAC

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.