RiskVulnerability

Patch Tuesday, May 2022

May 2022 Patch Tuesday update, including an important-rated zero-day bug that’s being actively exploited in the wild and several that are likely widely present across enterprises.

It also patched 7 critical flaws, 65 other important-rated bugs, and one low-severity issue. The fixes run the gamut of the computing giant’s portfolio, including Windows and Windows Components, .NET and Visual Studio, Microsoft Edge (Chromium-based), Microsoft Exchange Server, Office and Office Components, Windows Hyper-V, Windows Authentication Methods, BitLocker, Windows Cluster Shared Volume (CSV), Remote Desktop Client, Windows Network File System, NTFS, and Windows Point-to-Point Tunneling Protocol.

The actively exploited zero-day vulnerability fixed today is for a new NTLM Relay Attack using an LSARPC flaw tracked as ‘CVE-2022-26925 – Windows LSA Spoofing Vulnerability.’

“An unauthenticated attacker could call a method on the LSARPC interface and coerce the domain controller to authenticate to the attacker using NTLM. This security update detects anonymous connection attempts in LSARPC and disallows it,” explains Microsoft in an advisory published today.

Using this attack, threat actors can intercept legitimate authentication requests and use them to gain elevated privileges, even as far as assuming the identity of a domain controller.

Microsoft recommends admins read the PetitPotam NTLM Relay advisory for information on how to mitigate these types of attacks. The two publicly exposed zero-days are a denial of service vulnerability in Hyper-V and a new remote code execution Azure flaw.

Critical CVE Summary

  • CVE-2022-26925 – Windows LSA Spoofing Vulnerability.
  • CVE-2022-22713 – Windows Hyper-V Denial of Service Vulnerability
  • CVE-2022-29972 – Insight Software: CVE-2022-29972 Magnitude Simba Amazon Redshift ODBC Driver

Complete Summary

Azure vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-29972Insight Software: CVE-2022-29972 Magnitude Simba Amazon Redshift ODBC DriverNoYesN/AYes

Developer Tools vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-29148Visual Studio Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-30129Visual Studio Code Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2022-23267.NET and Visual Studio Denial of Service VulnerabilityNoNo7.5No
CVE-2022-29117.NET and Visual Studio Denial of Service VulnerabilityNoNo7.5No
CVE-2022-29145.NET and Visual Studio Denial of Service VulnerabilityNoNo7.5No
CVE-2022-30130.NET Framework Denial of Service VulnerabilityNoNo3.3No

ESU Windows vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-26935Windows WLAN AutoConfig Service Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2022-29121Windows WLAN AutoConfig Service Denial of Service VulnerabilityNoNo6.5Yes
CVE-2022-26936Windows Server Service Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2022-22015Windows Remote Desktop Protocol (RDP) Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2022-29103Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2022-29132Windows Print Spooler Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2022-26937Windows Network File System Remote Code Execution VulnerabilityNoNo9.8Yes
CVE-2022-26925Windows LSA Spoofing VulnerabilityYesYes8.1Yes
CVE-2022-22012Windows LDAP Remote Code Execution VulnerabilityNoNo9.8Yes
CVE-2022-29130Windows LDAP Remote Code Execution VulnerabilityNoNo9.8Yes
CVE-2022-22013Windows LDAP Remote Code Execution VulnerabilityNoNo8.8No
CVE-2022-22014Windows LDAP Remote Code Execution VulnerabilityNoNo8.8No
CVE-2022-29128Windows LDAP Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2022-29129Windows LDAP Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2022-29137Windows LDAP Remote Code Execution VulnerabilityNoNo8.8No
CVE-2022-29139Windows LDAP Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2022-29141Windows LDAP Remote Code Execution VulnerabilityNoNo8.8No
CVE-2022-26931Windows Kerberos Elevation of Privilege VulnerabilityNoNo7.5Yes
CVE-2022-26934Windows Graphics Component Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2022-29112Windows Graphics Component Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2022-22011Windows Graphics Component Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2022-29115Windows Fax Service Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-26926Windows Address Book Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-22019Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2022-21972Point-to-Point Tunneling Protocol Remote Code Execution VulnerabilityNoNo8.1Yes
CVE-2022-23270Point-to-Point Tunneling Protocol Remote Code Execution VulnerabilityNoNo8.1Yes
CVE-2022-29105Microsoft Windows Media Foundation Remote Code Execution VulnerabilityNoNo7.8No
CVE-2022-29127BitLocker Security Feature Bypass VulnerabilityNoNo4.2Yes

Exchange Server vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-21978Microsoft Exchange Server Elevation of Privilege VulnerabilityNoNo8.2Yes

Microsoft Office vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-29108Microsoft SharePoint Server Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2022-29107Microsoft Office Security Feature Bypass VulnerabilityNoNo5.5Yes
CVE-2022-29109Microsoft Excel Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-29110Microsoft Excel Remote Code Execution VulnerabilityNoNo7.8Yes

Windows vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-26930Windows Remote Access Connection Manager Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2022-29125Windows Push Notifications Apps Elevation of Privilege VulnerabilityNoNo7Yes
CVE-2022-29114Windows Print Spooler Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2022-29140Windows Print Spooler Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2022-29104Windows Print Spooler Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2022-22016Windows PlayToManager Elevation of Privilege VulnerabilityNoNo7Yes
CVE-2022-26933Windows NTFS Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2022-29131Windows LDAP Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2022-29116Windows Kernel Information Disclosure VulnerabilityNoNo4.7Yes
CVE-2022-29133Windows Kernel Elevation of Privilege VulnerabilityNoNo8.8Yes
CVE-2022-29142Windows Kernel Elevation of Privilege VulnerabilityNoNo7Yes
CVE-2022-29106Windows Hyper-V Shared Virtual Disk Elevation of Privilege VulnerabilityNoNo7Yes
CVE-2022-24466Windows Hyper-V Security Feature Bypass VulnerabilityNoNo4.1Yes
CVE-2022-22713Windows Hyper-V Denial of Service VulnerabilityNoYes5.6Yes
CVE-2022-26927Windows Graphics Component Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2022-29102Windows Failover Cluster Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2022-29113Windows Digital Media Receiver Elevation of Privilege VulnerabilityNoNo7.8Yes
CVE-2022-29134Windows Clustered Shared Volume Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2022-29120Windows Clustered Shared Volume Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2022-29122Windows Clustered Shared Volume Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2022-29123Windows Clustered Shared Volume Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2022-29138Windows Clustered Shared Volume Elevation of Privilege VulnerabilityNoNo7Yes
CVE-2022-29135Windows Cluster Shared Volume (CSV) Elevation of Privilege VulnerabilityNoNo7Yes
CVE-2022-29150Windows Cluster Shared Volume (CSV) Elevation of Privilege VulnerabilityNoNo7Yes
CVE-2022-29151Windows Cluster Shared Volume (CSV) Elevation of Privilege VulnerabilityNoNo7Yes
CVE-2022-26913Windows Authentication Security Feature Bypass VulnerabilityNoNo7.4Yes
CVE-2022-23279Windows ALPC Elevation of Privilege VulnerabilityNoNo7Yes
CVE-2022-29126Tablet Windows User Interface Application Core Elevation of Privilege VulnerabilityNoNo7Yes
CVE-2022-26932Storage Spaces Direct Elevation of Privilege VulnerabilityNoNo8.2Yes
CVE-2022-26938Storage Spaces Direct Elevation of Privilege VulnerabilityNoNo7Yes
CVE-2022-26939Storage Spaces Direct Elevation of Privilege VulnerabilityNoNo7Yes
CVE-2022-26940Remote Desktop Protocol Client Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2022-22017Remote Desktop Client Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2022-26923Active Directory Domain Services Elevation of Privilege VulnerabilityNoNo8.8Yes