KLA12524
Multiple vulnerabilities in Microsoft Products (ESU)

Updated: 04/07/2023
Detect date
?
05/10/2022
Severity
?
High
Description

Multiple vulnerabilities were found in Microsoft Products (Extended Security Update). Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information, bypass security restrictions, gain privileges, cause denial of service, spoof user interface.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Windows LDAP can be exploited remotely to execute arbitrary code.
  2. An information disclosure vulnerability in Windows Server Service can be exploited remotely to obtain sensitive information.
  3. A remote code execution vulnerability in Windows Fax Service can be exploited remotely to execute arbitrary code.
  4. A security feature bypass vulnerability in BitLocker can be exploited remotely to bypass security restrictions.
  5. An elevation of privilege vulnerability in Windows Kerberos can be exploited remotely to gain privileges.
  6. A remote code execution vulnerability in Remote Procedure Call Runtime can be exploited remotely to execute arbitrary code.
  7. An information disclosure vulnerability in Windows Graphics Component can be exploited remotely to obtain sensitive information.
  8. A remote code execution vulnerability in Windows Network File System can be exploited remotely to execute arbitrary code.
  9. An elevation of privilege vulnerability in Windows Remote Access Connection Manager can be exploited remotely to gain privileges.
  10. An information disclosure vulnerability in Windows Remote Desktop Protocol (RDP) can be exploited remotely to gain privileges.
  11. An elevation of privilege vulnerability in Windows Print Spooler can be exploited remotely to gain privileges.
  12. A remote code execution vulnerability in Windows Address Book can be exploited remotely to execute arbitrary code.
  13. A remote code execution vulnerability in Point-to-Point Tunneling Protocol can be exploited remotely to execute arbitrary code.
  14. A denial of service vulnerability in Windows WLAN AutoConfig Service can be exploited remotely to cause denial of service.
  15. A spoofing vulnerability in Windows LSA can be exploited remotely to to spoof user interface.
  16. A remote code execution vulnerability in Microsoft Windows Media Foundation can be exploited remotely to execute arbitrary code.
  17. An information disclosure vulnerability in Windows Graphics Component can be exploited remotely to gain privileges.
  18. An information disclosure vulnerability in Windows WLAN AutoConfig Service can be exploited remotely to gain privileges.
Exploitation

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Affected products

Windows Server 2008 for 32-bit Systems Service Pack 2
Windows 7 for 32-bit Systems Service Pack 1
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2022-29137
CVE-2022-26936
CVE-2022-29115
CVE-2022-29127
CVE-2022-22012
CVE-2022-26931
CVE-2022-22013
CVE-2022-22019
CVE-2022-29139
CVE-2022-29129
CVE-2022-29141
CVE-2022-29112
CVE-2022-26937
CVE-2022-29103
CVE-2022-22015
CVE-2022-29132
CVE-2022-29130
CVE-2022-26926
CVE-2022-23270
CVE-2022-29121
CVE-2022-21972
CVE-2022-26925
CVE-2022-29105
CVE-2022-22011
CVE-2022-26935
CVE-2022-29128
CVE-2022-26934
CVE-2022-22014

Impacts
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]

PE 
[?]

SUI 
[?]
Related products
Microsoft Windows
Microsoft Windows Server
Microsoft Windows 7
Microsoft Windows Server 2008
CVE-IDS
?
KB list

5014010
5013999
5014006
5014012

Microsoft official advisories
Microsoft Security Update Guide
Find out the statistics of the vulnerabilities spreading in your region