KLA12476
Multiple vulnerabilities in Microsoft Apps

Updated: 10/18/2022
Detect date
?
03/08/2022
Severity
?
Warning
Description

Multiple vulnerabilities were found in Microsoft Apps. Malicious users can exploit these vulnerabilities to bypass security restrictions, execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. A security feature bypass vulnerability in Microsoft Intune Portal for iOS can be exploited remotely to bypass security restrictions
  2. A remote code execution vulnerability in Paint 3D can be exploited remotely to execute arbitrary code.
Affected products

Microsoft Intune Portal
Paint 3D

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2022-24465
CVE-2022-23282

Impacts
?
ACE 
[?]

SB 
[?]
Related products
Microsoft Intune Portal
Paint 3D
Microsoft official advisories
Microsoft Security Update Guide
Find out the statistics of the vulnerabilities spreading in your region