• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Microsoft Fixes 71 Bugs Including Three Zero Days

You are here: Home / General Cyber Security News / Microsoft Fixes 71 Bugs Including Three Zero Days
March 9, 2022

Microsoft has produced fixes for a fairly tiny amount of CVEs this month, with only 3 critical bugs and a few publicly disclosed flaws in the Patch Tuesday roundup.

None of the a few zero times have been exploited in the wild. They include CVE-2022-24512, a distant code execution (RCE) vulnerability in .NET and Visual Studio.

“According to Microsoft, this vulnerability demands ‘under interaction’ to exploit, indicating that an attacker would probable require to add a payload to a susceptible method and then execute it remotely, somewhat than attacking the service immediately,” defined Recorded Upcoming senior security architect, Allan Liska.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper take secure and enxrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized seller: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


“This is possible why Microsoft has assigned it a criticality degree of ‘Important’ and rated it as ‘exploitation considerably less possible.’”

A different zero-working day patched this month is CVE-2022-24459, an elevation of privilege vulnerability in Microsoft’s Fax and Scan Provider, which is also rated “exploitation less most likely.”

The closing one particular is CVE-2022-21990, one more RCE bug but this time in the Distant Desktop Shopper and rated “exploitation far more possible.”

It’s a person of three CVEs this month impacting the distant desktop protocol (RDP), which has been closely specific for the duration of the pandemic.

“With the raise in distant doing the job driving the enlargement of the attack surface presented by RDP, a trio of RCE vulnerabilities impacting this protocol need to be on security teams’ radar,” argued Kev Breen, director of cyber-danger investigate at Immersive Labs.

“CVE-2022-23285, CVE-2022-21990 and CVE-2022-24503 are a opportunity concern particularly as this infection vector is normally applied by ransomware actors. When exploitation is not trivial, demanding an attacker to set up bespoke infrastructure, it continue to provides adequate of a risk to be a priority.”

Breen also flagged critical vulnerability CVE-2022-23277 as a priority.

“While necessitating authentication, this vulnerability affecting on-premises Exchange servers could probably be employed in the course of lateral movement into a portion of the natural environment which presents the possibility for small business email compromise or knowledge theft from email,” he mentioned.


Some parts of this post are sourced from:
www.infosecurity-journal.com

Previous Post: «critical rce bugs found in pascom cloud phone system used Critical RCE Bugs Found in Pascom Cloud Phone System Used by Businesses
Next Post: Chinese APT41 Hackers Broke into at Least 6 U.S. State Governments: Mandiant chinese apt41 hackers broke into at least 6 u.s. state»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • FBI, CISA Warn of Russian Hackers Exploiting MFA and PrintNightmare Bug
  • Unpatched RCE Bug in dompdf Project Affects HTML to PDF Converters
  • NortonLifeLock and Avast merger could reduce competition, CMA warns
  • Thousands of Mobile Apps Expose User Data Via Cloud Misconfigurations
  • NSW ditches e-voting system for 2023 election
  • Kaspersky Hits Back at “Politically Motivated” BSI Advisory
  • Germany advises against using Kaspersky software due to hacking risk
  • CISA: Fix MFA and Patch Promptly to Stop Russian Attackers
  • German Government Warns Against Using Russia’s Kaspersky Antivirus Software
  • Multiple Flaws Uncovered in ClickHouse OLAP Database System for Big Data

Copyright © TheCyberSecurity.News, All Rights Reserved.