Threat Advisory

Microsoft Quashes Actively Exploited Zero-Day, Wormable Critical Bugs

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

Microsoft has released a patch for pair of zero day and wormable vulnerabilities which of one was actively exploited in attacks (CVE-2022-37969 - Windows Common Log File System Driver Elevation of Privilege Vulnerability) if attacker successfully exploited this vulnerability could gain SYSTEM privileges. Another zero-day bug (CVE-2022-23960) if exploited , could give attacker access to sensitive information. The other critical bugs are wormable that means they can spread infection from one computer to another without any user interaction, (CVE-2022-34718) it allows a remote unauthenticated attacker to execute code with elevated privileges on affected systems without user interaction, (CVE-2022-34722 and CVE-2022-34721) they allow RCE by sending a specially crafted IP packet to a target and last two were (CVE-2022-34700 and CVE-2022-35805) both exist in Dynamics 365 On-Premises, and could allow an authenticated user to perform SQL injection attacks and execute commands.[/subscribe_to_unlock_form]

Summary:

Microsoft has released a patch for pair of zero day and wormable vulnerabilities which of one was actively exploited in attacks (CVE-2022-37969 - Windows Common Log File System Driver Elevation of Privilege Vulnerability) if attacker successfully exploited this vulnerability could gain SYSTEM privileges. Another zero-day bug (CVE-2022-23960) if exploited , could give attacker access to sensitive information. The other critical bugs are wormable that means they can spread infection from one computer to another without any user interaction, (CVE-2022-34718) it allows a remote unauthenticated attacker to execute code with elevated privileges on affected systems without user interaction, (CVE-2022-34722 and CVE-2022-34721) they allow RCE by sending a specially crafted IP packet to a target and last two were (CVE-2022-34700 and CVE-2022-35805) both exist in Dynamics 365 On-Premises, and could allow an authenticated user to perform SQL injection attacks and execute commands.[emaillocker id="1283"]

References:

The following reports contain further technical details:

https://www.darkreading.com/vulnerabilities-threats/microsoft-quashes-actively-exploited-zero-day-wormable-critical-bugs

[/emaillocker]
crossmenu