Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Blue Chip NFTs 101 – How Did Moonbirds Conquer The World In A Bearish Market? bitcoin news
  • Freedom Protocol Has Become the Project With the Largest Amount of IDO in the Ecology of Binance Smart Chain – Press release Bitcoin News bitcoin news
  • Electrifying Live Casino Game XXXtreme Lightning Roulette in Exclusive Early Access – Promoted Bitcoin News bitcoin news
  • Researchers Warn of Nerbian RAT Targeting Entities in Italy, Spain, and the U.K cyber security news
  • U.S. Warns Against North Korean Hackers Posing as IT Freelancers cyber security news
  • Truly Playable AAA Games to Look Forward to in 2022 bitcoin news
  • North Korean Hackers Target Journalists with GOLDBACKDOOR Malware cyber security news
  • US Economy Is Probably in Recession That Could Last 18 Months — Warns It ‘Will Get Worse’ – Economics Bitcoin News bitcoin news

Microsoft Releases Fix for New Zero-Day with May 2022 Patch Tuesday Updates

Posted on May 11, 2022 By root


Patch Tuesday Updates

Microsoft on Tuesday rolled out fixes for as many as 74 security vulnerabilities, including one for a zero-day bug that’s being actively exploited in the wild.

Of the 74 issues, seven are rated Critical, 66 are rated Important, and one is rated low in severity. Two of the flaws are listed as publicly known at the time of release.

These encompass 24 remote code execution (RCE), 21 elevation of privilege, 17 information disclosure, and six denial-of-service vulnerabilities, among others. The updates are in addition to 36 flaws patched in the Chromium-based Microsoft Edge browser on April 28, 2022.

Chief among the resolved bugs is CVE-2022-26925 (CVSS score: 8.1), a spoofing vulnerability affecting the Windows Local Security Authority (LSA), which Microsoft describes as a “protected subsystem that authenticates and logs users onto the local system.”

“An unauthenticated attacker could call a method on the LSARPC interface and coerce the domain controller to authenticate to the attacker using NTLM,” the company said. “This security update detects anonymous connection attempts in LSARPC and disallows it.”

It’s also worth noting that the CVSS severity rating of the flaw would be elevated to 9.8 should it be combined with NTLM relay attacks like PetitPotam, making it a critical issue.

“Being actively exploited in the wild, this exploit allows an attacker to authenticate as approved users as part of an NTLM relay attack – letting threat actors gain access to the hashes of authentication protocols,” Kev Breen, director of cyber threat research at Immersive Labs, said.

The two other publicly-known vulnerabilities are as follows –

  • CVE-2022-29972 (CVSS score: 8.2) – Insight Software: CVE-2022-29972 Magnitude Simba Amazon Redshift ODBC Driver (aka SynLapse)
  • CVE-2022-22713 (CVSS score: 5.6) – Windows Hyper-V Denial-of-Service Vulnerability

Microsoft, which remediated CVE-2022-29972 on April 15, tagged it as “Exploitation More Likely” on the Exploitability Index, making it imperative affected users apply the updates as soon as possible.

Also patched by Redmond are several RCE bugs in Windows Network File System (CVE-2022-26937), Windows LDAP (CVE-2022-22012, CVE-2022-29130), Windows Graphics (CVE-2022-26927), Windows Kernel (CVE-2022-29133), Remote Procedure Call Runtime (CVE-2022-22019), and Visual Studio Code (CVE-2022-30129).

Cyber-Kunlun, a Beijing-based cybersecurity company, has been credited with reporting 30 of the 74 flaws, counting CVE-2022-26937, CVE-2022-22012, and CVE-2022-29130.

What’s more, CVE-2022-22019 followed an incomplete patch for three RCE issues in the Remote Procedure Call (RPC) runtime library last month — CVE-2022-26809, CVE-2022-24492, and CVE-2022-24528 — that were addressed by Microsoft in April 2022.

Exploiting the flaw would allow a remote, unauthenticated attacker to execute code on the vulnerable machine with the privileges of the RPC service, Akamai said.

The Patch Tuesday update is also notable for resolving two privilege escalation (CVE-2022-29104 and CVE-2022-29132) and two information disclosure (CVE-2022-29114 and CVE-2022-29140) vulnerabilities in the Print Spooler component, which has long posed an attractive target for attackers.

Software Patches from Other Vendors

Besides Microsoft, security updates have also been released by other vendors since the start of the month to rectify several vulnerabilities, including —





TheHackersNews/

cyber security news

Post navigation

Previous Post: Asia Broadband’s Holdings Explode by 500% as the Company Continues Connecting the Dots Between Gold and Digital Assets
Next Post: Ukraine’s New Fundraising Platform Accepts Crypto, Allows Donors to Allocate Funds – Bitcoin News

Related Posts

  • Twitter’s New Owner Elon Musk Wants DMs to be End-to-End Encrypted like Signal cyber security news
  • E.U. Blames Russia for Cyberattack on KA-SAT Satellite Network Operated by Viasat cyber security news
  • QNAP Advises to Mitigate Remote Hacking Flaws Until Patches are Available cyber security news
  • Researchers Find Way to Run Malware on iPhone Even When It’s OFF cyber security news
  • New Sysrv Botnet Variant Hijacking Windows and Linux with Crypto Miners cyber security news
  • 5 Benefits of Detection-as-Code cyber security news

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Hackers Trick Users with Fake Windows 11 Downloads to Distribute Vidar Malware
  • Cyprus Drafts Crypto Rules, May Introduce Them Before EU Regulations – Regulation Bitcoin News
  • MetaOasis AVAX Hackathon News Report – Press release Bitcoin News
  • Pakistan Can Generate $90 Million Annually if It Introduces a 15% Tax on Crypto Transactions – Emerging Markets Bitcoin News
  • QNAP Urges Users to Update NAS Devices to Prevent Deadbolt Ransomware Attacks

Recent Comments

No comments to show.
  • Drunk Robots Announces 4 Massive New Partnerships and a 5,000,000 $METAL Battle Prize Pool bitcoin news
  • Infinite Arcade Launches the Last Sale of the Gamer NFTs – Sponsored Bitcoin News bitcoin news
  • Ukrainian CERT Warns Citizens of a New Wave of Attacks Distributing Jester Malware cyber security news
  • Microsoft Documents Over 200 Cyberattacks by Russia Against Ukraine cyber security news
  • Australian Taxation Office to Focus on Capital Gains From Crypto Assets – Taxes Bitcoin News bitcoin news
  • Robinhood Launching New Non-Custodial Web3 Crypto Wallet – Wallets Bitcoin News bitcoin news
  • StreamCoin Announces 200M STRM Corporate ICO Investment by TNC IT Group – Press release Bitcoin News bitcoin news
  • Recent Bitcoin Bull Run and Prior Run-up Data Suggests a Softer Bear Market Is in the Cards – Market Updates Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme