
Microsoft patched 84 CVEs in its July 2022 Patch Tuesday release, with four rated as critical, 79 rated as important and one rated as unknown.
This month’s update includes patches for:
- AMD CPU Branch
- Azure Site Recovery
- Azure Storage Library
- Microsoft Defender for Endpoint
- Microsoft Edge (Chromium-based)
- Microsoft Graphics Component
- Microsoft Office
- Open-Source Software
- Role: DNS Server
- Role: Windows Fax Service
- Role: Windows Hyper-V
- Skype for Business and Microsoft Lync
- Windows Active Directory
- Windows Advanced Local Procedure Call
- Windows BitLocker
- Windows Boot Manager
- Windows Client/Server Runtime Subsystem
- Windows Connected Devices Platform Service
- Windows Credential Guard
- Windows Fast FAT Driver
- Windows Fax and Scan Service
- Windows Group Policy
- Windows IIS
- Windows Kernel
- Windows Media
- Windows Network File System
- Windows Performance Counters
- Windows Point-to-Point Tunnelling Protocol
- Windows Portable Device Enumerator Service
- Windows Print Spooler Components
- Windows Remote Procedure Call Runtime
- Windows Security Account Manager
- Windows Server Service
- Windows Shell
- Windows Storage
- Xbox
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-33675 is an EoP vulnerability in Azure Site Recovery, a suite of tools aimed at providing disaster recovery services. It exists due to a directory permission error which can allow an attacker to use DLL hijacking to elevate their privileges to the SYSTEM
Windows CSRSS Elevation of Privilege
CVE-2022-22047 is an EoP vulnerability in the Windows Client Server Run-Time Subsystem with a CVSSv3 score of 7.8 and is rated as Important. Microsoft says this vulnerability has been exploited in the wild, though no further details have been shared at the time of publication. However, this type of vulnerability is likely to have been used as part of post-compromise activity once an attacker has gained access to their targeted system and run a specially crafted application.
Windows Print Spooler Elevation of Privilege Vulnerabilities
CVE-2022-22022, CVE-2022-22041, CVE-2022-30206, and CVE-2022-30226 are all EoP vulnerabilities in Windows Print Spooler Components. After the deluge of vulnerability disclosures kicked off by PrintNightmare in August 2021, June 2022 was the first month in which Microsoft did not release any patches for Print Spooler. On balance, Microsoft has patched four high severity vulnerabilities in the service, all of which were rated “Exploitation Less Likely” based on Microsoft’s Exploitability Index.
CVE ID | Description | CVSS |
CVE-2022-22022 | Windows Print Spooler Elevation of Privilege | 7.1 |
CVE-2022-22041 | Windows Print Spooler Elevation of Privilege | 7.2 |
CVE-2022-30206 | Windows Print Spooler Elevation of Privilege | 7.8 |
CVE-2022-30226 | Windows Print Spooler Elevation of Privilege | 7.1 |
If patching is not feasible at this time, all four vulnerabilities can be mitigated by disabling the Print Spooler service.
Remote Procedure Call Runtime Remote Code Execution Vulnerability
CVE-2022-22038 is an RCE vulnerability in the Remote Procedure Call Runtime impacting all supported versions of Windows. The vulnerability received a CVSSv3 score of 8.1 and, while no privileges are required, the CVSS score indicates the attack complexity is high. Microsoft further supports this with a note in the advisory stating that additional actions by an attacker are required to prepare a target for successful exploitation.
Windows Network File System Vulnerabilities
CVE-2022-22028 is an information disclosure vulnerability, while CVE-2022-22029 and CVE-2022-22039are RCE vulnerabilities in the Windows Network File System (NFS) and Exploitation Less Likely because these flaws have high attack complexity. In the case of CVE-2022-22029, an attacker would need to invest time in repeated exploitation attempts by sending constant or intermittent data. Both CVE-2022-22028 and CVE-2022-22039 require an attacker to win a race condition to exploit these vulnerabilities.
Chromium Edge
Earlier in July, Microsoft released Microsoft Edge (Chromium-based) vulnerabilities CVE-2022-2294 and CVE-2022-2295. The vulnerability assigned to each of these CVEs is in the Chromium Open Source Software (OSS) which is consumed by Microsoft Edge. It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
CVE ID | Description | Severity |
CVE-2022-23825 | AMD: CVE-2022-23825 AMD CPU Branch Type Confusion | Important |
CVE-2022-23816 | AMD: CVE-2022-23816 AMD CPU Branch Type Confusion | Important |
CVE-2022-33665 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33666 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33663 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33664 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33667 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33672 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33673 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33671 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33668 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33661 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33662 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33657 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33656 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33658 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33660 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33659 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33655 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33651 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33650 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33652 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33654 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33653 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33669 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33643 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-30181 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33676 | Azure Site Recovery Remote Code Execution Vulnerability | Important |
CVE-2022-33677 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33678 | Azure Site Recovery Remote Code Execution Vulnerability | Important |
CVE-2022-33642 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33674 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33675 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-33641 | Azure Site Recovery Elevation of Privilege Vulnerability | Important |
CVE-2022-30187 | Azure Storage Library Information Disclosure Vulnerability | Important |
CVE-2022-33637 | Microsoft Defender for Endpoint Tampering Vulnerability | Important |
CVE-2022-2295 | Chromium: CVE-2022-2295 Type Confusion in V8 | Unknown |
CVE-2022-2294 | Chromium: CVE-2022-2294 Heap buffer overflow in WebRTC | Unknown |
CVE-2022-22034 | Windows Graphics Component Elevation of Privilege Vulnerability | Important |
CVE-2022-30213 | Windows GDI+ Information Disclosure Vulnerability | Important |
CVE-2022-30221 | Windows Graphics Component Remote Code Execution Vulnerability | Critical |
CVE-2022-33632 | Microsoft Office Security Feature Bypass Vulnerability | Important |
CVE-2022-27776 | HackerOne: CVE-2022-27776 Insufficiently protected credentials vulnerability might leak authentication or cookie header data | Important |
CVE-2022-30214 | Windows DNS Server Remote Code Execution Vulnerability | Important |
CVE-2022-22024 | Windows Fax Service Remote Code Execution Vulnerability | Important |
CVE-2022-22027 | Windows Fax Service Remote Code Execution Vulnerability | Important |
CVE-2022-30223 | Windows Hyper-V Information Disclosure Vulnerability | Important |
CVE-2022-22042 | Windows Hyper-V Information Disclosure Vulnerability | Important |
CVE-2022-33633 | Skype for Business and Lync Remote Code Execution Vulnerability | Important |
CVE-2022-30215 | Active Directory Federation Services Elevation of Privilege Vulnerability | Important |
CVE-2022-30202 | Windows Advanced Local Procedure Call Elevation of Privilege Vulnerability | Important |
CVE-2022-30224 | Windows Advanced Local Procedure Call Elevation of Privilege Vulnerability | Important |
CVE-2022-22037 | Windows Advanced Local Procedure Call Elevation of Privilege Vulnerability | Important |
CVE-2022-22711 | Windows BitLocker Information Disclosure Vulnerability | Important |
CVE-2022-22048 | BitLocker Security Feature Bypass Vulnerability | Important |
CVE-2022-30203 | Windows Boot Manager Security Feature Bypass Vulnerability | Important |
CVE-2022-22026 | Windows CSRSS Elevation of Privilege Vulnerability | Important |
CVE-2022-22049 | Windows CSRSS Elevation of Privilege Vulnerability | Important |
CVE-2022-22047 | Windows CSRSS Elevation of Privilege Vulnerability | Important |
CVE-2022-30212 | Windows Connected Devices Platform Service Information Disclosure Vulnerability | Important |
CVE-2022-22031 | Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability | Important |
CVE-2022-22043 | Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | Important |
CVE-2022-22050 | Windows Fax Service Elevation of Privilege Vulnerability | Important |
CVE-2022-30205 | Windows Group Policy Elevation of Privilege Vulnerability | Important |
CVE-2022-30209 | Windows IIS Server Elevation of Privilege Vulnerability | Important |
CVE-2022-22025 | Windows Internet Information Services Cachuri Module Denial of Service Vulnerability | Important |
CVE-2022-22040 | Internet Information Services Dynamic Compression Module Denial of Service Vulnerability | Important |
CVE-2022-21845 | Windows Kernel Information Disclosure Vulnerability | Important |
CVE-2022-22045 | Windows.Devices.Picker.dll Elevation of Privilege Vulnerability | Important |
CVE-2022-30225 | Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability | Important |
CVE-2022-22029 | Windows Network File System Remote Code Execution Vulnerability | Critical |
CVE-2022-22028 | Windows Network File System Information Disclosure Vulnerability | Important |
CVE-2022-22039 | Windows Network File System Remote Code Execution Vulnerability | Critical |
CVE-2022-22036 | Performance Counters for Windows Elevation of Privilege Vulnerability | Important |
CVE-2022-30211 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | Important |
CVE-2022-22023 | Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability | Important |
CVE-2022-30206 | Windows Print Spooler Elevation of Privilege Vulnerability | Important |
CVE-2022-30226 | Windows Print Spooler Elevation of Privilege Vulnerability | Important |
CVE-2022-22022 | Windows Print Spooler Elevation of Privilege Vulnerability | Important |
CVE-2022-22041 | Windows Print Spooler Elevation of Privilege Vulnerability | Important |
CVE-2022-22038 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Critical |
CVE-2022-30208 | Windows Security Account Manager (SAM) Denial of Service Vulnerability | Important |
CVE-2022-30216 | Windows Server Service Tampering Vulnerability | Important |
CVE-2022-30222 | Windows Shell Remote Code Execution Vulnerability | Important |
CVE-2022-30220 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important |
CVE-2022-33644 | Xbox Live Save Service Elevation of Privilege Vulnerability | Important |