Microsoft released a security update under the November Patch Tuesday with the fixes of 68 security vulnerabilities including 6 actively exploited zero-days that affect several Microsoft products.
In this list of Vulnerabilities, 12 Vulnerabilities were marked as “Critical”, 2 were listed under “High” and the rest of the 55 vulnerabilities were fixed as “Important”.
Here the following Microsoft Portifolio products that receives a security updates for its respective bugs:-
Fixed bugs are cantogorized under the following severities:-
Microsoft fixed 6 zero-day vulnerabilities in this update that affects various MS products.
CVE-2022-41040 – A Microsoft Exchange Server Elevation of Privilege vunerability that allow attackers to execute a powershell in the Context of the system, discovered and reported by Zero-day initiative Team under GTSC program.
CVE-2022-41128 – Windows Scripting Languages Remote Code Execution Vulnerability that required attackers to host a specially crafted website or server where they trick users to visit from affected version of Windows to exploit and gain access.
CVE-2022-41082 – Microsoft Exchange Server Remote Code Execution Vulnerability let hackers to execute the remote code on the targeted server accounts and the successful gain leads to the attacker could attempt to trigger malicious code with the help of network call.
CVE-2022-41073 – Windows Print Spooler Elevation of Privilege Vulnerability allow attackers to exploit the vulnerability to gaint he system previledges.
CVE-2022-41091 – Windows Mark of the Web Security Feature Bypass Vulnerability allows AN attacker can craft a malicious file that would evade Mark of the Web (MOTW) defenses.
CVE-2022-41125 – Windows CNG Key Isolation Service Elevation of Privilege Vulnerability that uncovered by Microsoft internal security team and the vulnerabilities allow attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Other vendors who released updates in November 2022 include:
Microsoft strongly recommended installing these security updates for all windows users to avoid the security risk and protect your Windows.
You can refer to the complete patch details for the full list of vulnerabilities resolved, and advisories, in the November 2022 Patch here.
Azure Active Directory Security – Download Free E-Book
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…