Microsoft released its monthly security update on Tuesday 12th April 2022, patching 128 issues across its suite of products.
This Patch Tuesday, the breakdown of vulnerabilities includes 10 Critical issues, with the remaining 115 being labelled as Important. There has been one actively exploited flaw (CVE-2022-24521, CVSS score: 7.8) and relates to an elevation of privilege vulnerability in the Windows Common Log File System (CLFS).
The main critical vulnerabilities to note are addressed below:
- CVE-2022-24521 – Relates to an elevation of privilege vulnerability in the Windows Common Log File System (CLFS)
- CVE-2022-26904 – Concerns a case of privilege escalation in the Windows User Profile Service, successful exploitation of which “requires an attacker to win a race condition.”
- CVE-2022-26809 – Remote code execution vulnerability that affects the RPC Runtime Library
- CVE-2022-24491and CVE-2022-24497 – Remote code execution vulnerability that affects the Windows Network File System
- CVE-2022-24541 – Remote code execution vulnerability that affects the Windows Server Service
- CVE-2022-24500 – Remote code execution vulnerability that affects Windows SMB
- CVE-2022-23259 – Remote code execution vulnerability that affects Microsoft Dynamics 365
As reported by The Hacker News, this month’s patches addressed 18 flaws in Windows DNS Server, 1 information disclosure flaw and 17 remote code execution flaws.
A full list of Microsoft’s April 2022 patches can be found here: Microsoft Security Response Centre