Breaking

Microsoft Patch Tuesday February 2022 fixes 51 vulnerabilities

Microsoft Patch Tuesday February 2022 comes with fixes for 51 vulnerabilities across Windows Office, Azure Data Explorer, Teams, Visual Studio Code, Kernal and Win32K.

The Patch Tuesday has 51 defects closed, out of which 50 are considered important and one is mentioned as Moderate. All these come with 19 more flaws the company fixed in the Chromium-based Edge browser.

Detailed breakdown of Microsoft Patch Tuesday February 2022 updates

The security vulnerabilities fixed in this Microsoft Patch Tuesday February 2022 update are not actively exploited in the wild, the flaw CVE-2022-21989 with CVSS score 7.8 has been mentioned as Zero-Day. The issue is a privileged escalation bug in Windows Kernel with Microsoft warning of potential attacks.

Once this vulnerability is successfully exploited the attacker can perform other actions for further exploitation of the network. The attack can be performed from a low privilege AppContainer allowing elevated privileges and execute code or access resources at next level.

Besides that, there are several remote code execution vulnerabilities affecting,

The Microsoft Patch Tuesday February 2022 security update also comes with fixes for,

  • Azure Data Explorer spoofing vulnerability – CVE-2022-23256 with CVSS score of 8.1
  • Two security bypass vulnerabilities impacting Outlook for Mac – CVE-2022-23280 with CVSS score of 5.3
  • Two DOS vulnerabilities in.NET – CVE-2022-21986 with CVSS score of 7.5
  • OneDrive for Android CVE-2022-23255 with CVSS score of 5.9
  • Teams – CVE-2022-21965 with CVSS score of 7.5

Fixing the multiple elevated privilege flaws in Print Spooler Service and one in the Win32K driver – CVE-2022-21966 with a CVSS score of 7.8, the latter has been mentioned as ‘Exploitation More Likely’ which was patched in Microsoft Patch Tuesday Jan 2022 in CVE-2022-21882.

The Patch Tuesday update came with a patch that was addressing the vulnerability from 2013, which is a signature validation issue affecting WinVerifyTrust CVE-2013-3900 with the fix coming as a opt-in feature via reg key setting, and is now supported editions of Windows released right after December 10, 2013.

The current ZLoader malware campaign that uncovered by Check Point Research in early January was found exploiting the flaw to bypass the file signature verification mechanism and drop malware that can siphon user credentials and other sensitive information.

If you need complete details on the Microsoft Patch Tuesday February 2022 vulnerabilities please visit Microsoft website.

Subscribe to our newsletter for daily alerts on cyber events, you can also follow us on Facebook, Linkedin, Instagram, Twitter and Reddit.

You can reach out to us via Twitter or Facebook, for any advertising requests.

Share the article with your friends
John Greenwood

He has been working with Cybersec and Infosec market for 12+ years now. Passionate about AI, Cybersecurity, Info security, Blockchain and Machine Learning. When he is not occupied with cybersecurity, he likes to go on bike rides!

Recent Posts

Top 11 Log Management Tools for Efficient System Management

Discover the top 11 log management tools for efficient system management and monitoring. Learn about…

3 weeks ago

Top 5 Threat Intelligence Tools For 2024

Explore the top 5 threat intelligence tools, their features, and how they enhance cybersecurity against…

3 weeks ago

Privileged Access Management: 5 Best PAM Solutions in the Market

Explore the top 5 best PAM Tools, market trends, and expert insights to secure the…

1 month ago

Apple Device Management: Top Solutions for iOS and macOS Management

Explore the top solutions for Apple Device Management including to iOS Device Management and macOS…

1 month ago

IAM Software: Top 5 IAM Solutions for Enterprise Security

Find the top 5 IAM software solutions, explore their features, and find the best tools…

1 month ago

Top 5 MDM Tools for 2024 – Best Mobile Device Management Software

MDM software is used to manage smartphones, tablets, laptops, kiosk devices and iPads and more.…

1 month ago