{"id":39321,"date":"2022-07-13T06:30:00","date_gmt":"2022-07-13T06:30:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/39321"},"modified":"2022-07-13T06:30:00","modified_gmt":"2022-07-13T06:30:00","slug":"july-patch-tuesday-brings-more-than-80-fixes-one-zero-day","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=39321","title":{"rendered":"July Patch Tuesday brings more than 80 fixes, one zero-day"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/07\/july-patch-tuesday-brings-more-than-80-fixes-one-zero-day.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Microsoft customers with Windows Enterprise E3 and E5 licences can now take advantage of automated patching with Redmond\u2019s Windows Autopatch service \u2013 <a href=\"https:\/\/www.computerweekly.com\/news\/252522608\/Microsoft-Windows-Autopatch-now-generally-available\">formally launched yesterday<\/a> (12 July) but for everybody else, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/\">the latest Patch Tuesday update<\/a> brings more than 80 fixes, including one actively exploited zero-day to which attention must be paid.<\/p>\n<p>Tracked as <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-22047\">CVE-2022-22047<\/a>, the zero-day is in Windows Client Server Runtime Process (CSRSS), a highly important part of every Windows operating system that manages several critical processes.<\/p>\n<p>Fortunately, successful exploitation requires an attacker to have an existing foothold on the target\u2019s systems, so it carries a comparatively low CVSS score of just 7.8. However, Microsoft said it is under active attack and if successfully exploited, could allow the attacker to execute code with SYSTEM-level privileges.<\/p>\n<p>Assessing the potential impact of CVE-2022-22047, <a href=\"https:\/\/www.immersivelabs.com\/\">Immersive Labs\u2019<\/a> Kev Breen said: \u201cThis kind of vulnerability is typically seen after a target has already been compromised. Crucially, it allows the attacker to escalate their permissions from that of a normal user to the same permissions as the SYSTEM.<\/p>\n<p>\u201cWith this level of access, the attackers are able to disable local services such as endpoint detection and security tools. With SYSTEM access they can also deploy tools like Mimikatz which can be used to recover even more admin and domain level accounts, spreading the threat quickly,\u201d said Breen.<\/p>\n<p>Mike Walters, co-founder of <a href=\"https:\/\/www.action1.com\/\">Action1<\/a>, a supplier of cloud remote monitoring and management services, added: \u201cVulnerabilities of this type are great for taking control over a workstation or server when they are paired with phishing attacks that use Office documents with macros. This vulnerability can likely be <a href=\"https:\/\/www.computerweekly.com\/news\/252520855\/Researchers-discover-zero-day-Microsoft-vulnerability-in-Office\">combined with Follina<\/a> to gain full control over a Windows endpoint.\u201d<\/p>\n<p>The value of macros in successfully crafting an attack that exploits CVE-2022-22047 will make it of additional concern for many, given Microsoft\u2019s <a href=\"https:\/\/www.computerweekly.com\/news\/252522508\/Microsoft-appears-to-reverse-VBA-macro-blocking\">suspension of its new policy to block macros by default<\/a> late last week, <a href=\"https:\/\/www.computerweekly.com\/news\/252522559\/Microsoft-VBA-macro-block-will-return\">apparently only temporarily<\/a>.<\/p>\n<p>Elsewhere, Redmond\u2019s July drop contains fixes for four critical vulnerabilities, all of which enable remote code execution. These are, in numerical order, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-22029\">CVE-2022-22029<\/a> in Windows Network File System; <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-22038\">CVE-2022-22038<\/a> in Remote Procedure Call Runtime; <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-22039\">CVE-2022-22039<\/a>, also in Windows Network File System; and finally, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-30221\">CVE-2022-30221<\/a> in Windows Graphics Component.<\/p>\n<p>Of these four vulnerabilities, the first three would be relatively tricky for attackers to exploit because they require a large amount of sustained data to be transmitted, while the fourth requires an attacker to run a malicious remote desktop (RDP) server, and convince a user to connect to it. \u201cThis is not as far-fetched as it first sounds,\u201d said Breen. \u201cAs RDP shortcut files could be emailed to target victims, and these file types may not flag as malicious by email scanners and filters.\u201d<\/p>\n<p>Looking beyond the most impactful vulnerabilities, the July drop is also notable for a high number of fixes that address a whopping 33 elevation of privilege vulnerabilities in the Azure Site Recovery service.<\/p>\n<p>None of these vulnerabilities are being actively exploited, but according to Chris Goettl of <a href=\"https:\/\/www.ivanti.com\/blog\/may-patch-tuesday-2022\">Ivanti<\/a>, they are highly problematic. \u201cThe concern is in the number of vulnerabilities resolved,\u201d he said. \u201cThey were identified by several independent researchers and anonymous parties, which means the knowledge of how to exploit these vulnerabilities is a bit more broadly distributed.<\/p>\n<p>\u201c<a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/site-recovery\/vmware-azure-manage-process-server#upgrade-a-process-server\">The resolution is also not simple<\/a>. It requires signing into each process server as an administrator, downloading and installing the latest version. Vulnerabilities like this are often easy to lose track of as they are not managed by the typical patch management process.\u201d<\/p>\n<p>Goettl also called out four print-spooler vulnerabilities \u2013 again none previously disclosed or exploited, but still risky in terms of the disruption they could potentially cause to organisations. \u201c<a href=\"https:\/\/www.computerweekly.com\/news\/252503494\/Should-I-be-worried-about-PrintNightmare\">Since PrintNightmare<\/a>, there have been many Print Spooler fixes, and in more than one of those Patch Tuesday events the changes have resulted in operational impacts,\u201d he said.<\/p>\n<p>\u201cThis makes administrators a little gun-shy and warrants some extra testing to ensure no negative issues occur in their organisation,\u201d said Goettl. \u201cThe bigger risk is if this blocks an organisation from pushing the July OS update it could prevent resolving critical vulnerabilities and the zero-day vulnerability CVE-2022-22047, which is also included in the cumulative OS update.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft customers with Windows Enterprise E3 and E5 licences can now take advantage of automated patching with Redmond\u2019s Windows Autopatch service \u2013 formally launched yesterday (12 July) but for everybody else, the latest Patch Tuesday update brings more than 80 fixes, including one actively exploited zero-day to which attention must be paid. Tracked as CVE-2022-22047, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":39322,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-39321","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/39321","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=39321"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/39321\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/39322"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=39321"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=39321"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=39321"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}