KLA12526
Multiple vulnerabilities in Microsoft Windows

Updated: 05/23/2022
Detect date
?
05/10/2022
Severity
?
High
Description

Multiple vulnerabilities were found in Microsoft Windows. Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information, bypass security restrictions, gain privileges, spoof user interface, cause denial of service.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Windows LDAP can be exploited remotely to execute arbitrary code.
  2. An information disclosure vulnerability in Windows Print Spooler can be exploited remotely to obtain sensitive information.
  3. An elevation of privilege vulnerability in Windows Hyper-V Shared Virtual Disk can be exploited remotely to None.
  4. A security feature bypass vulnerability in BitLocker can be exploited remotely to bypass security restrictions.
  5. A remote code execution vulnerability in Remote Procedure Call Runtime can be exploited remotely to execute arbitrary code.
  6. A remote code execution vulnerability in Remote Desktop Client can be exploited remotely to None.
  7. An elevation of privilege vulnerability in Windows Print Spooler can be exploited remotely to None.
  8. An information disclosure vulnerability in Windows Failover Cluster can be exploited remotely to None.
  9. An elevation of privilege vulnerability in Windows Cluster Shared Volume (CSV) can be exploited remotely to None.
  10. An information disclosure vulnerability in Windows Clustered Shared Volume can be exploited remotely to None.
  11. An elevation of privilege vulnerability in Windows Print Spooler can be exploited remotely to gain privileges.
  12. A remote code execution vulnerability in Windows Graphics Component can be exploited remotely to None.
  13. A spoofing vulnerability in Windows LSA can be exploited remotely to to spoof user interface.
  14. A remote code execution vulnerability in Microsoft Windows Media Foundation can be exploited remotely to execute arbitrary code.
  15. An elevation of privilege vulnerability in Windows Digital Media Receiver can be exploited remotely to None.
  16. An information disclosure vulnerability in Windows Graphics Component can be exploited remotely to gain privileges.
  17. An elevation of privilege vulnerability in Windows ALPC can be exploited remotely to None.
  18. An elevation of privilege vulnerability in Windows Kernel can be exploited remotely to gain privileges.
  19. An information disclosure vulnerability in Windows Server Service can be exploited remotely to obtain sensitive information.
  20. A remote code execution vulnerability in Windows Fax Service can be exploited remotely to execute arbitrary code.
  21. An elevation of privilege vulnerability in Windows Kerberos can be exploited remotely to gain privileges.
  22. An elevation of privilege vulnerability in Windows Push Notifications Apps can be exploited remotely to None.
  23. A denial of service vulnerability in Windows Hyper-V can be exploited remotely to None.
  24. An elevation of privilege vulnerability in Windows Clustered Shared Volume can be exploited remotely to gain privileges.
  25. An information disclosure vulnerability in Windows Graphics Component can be exploited remotely to obtain sensitive information.
  26. An elevation of privilege vulnerability in Windows Remote Access Connection Manager can be exploited remotely to gain privileges.
  27. A remote code execution vulnerability in Windows Network File System can be exploited remotely to execute arbitrary code.
  28. An information disclosure vulnerability in Windows Remote Desktop Protocol (RDP) can be exploited remotely to gain privileges.
  29. An information disclosure vulnerability in Windows NTFS can be exploited remotely to None.
  30. An elevation of privilege vulnerability in Windows Cluster Shared Volume (CSV) can be exploited remotely to gain privileges.
  31. A security feature bypass vulnerability in Windows Hyper-V can be exploited remotely to None.
  32. An information disclosure vulnerability in Remote Desktop Protocol Client can be exploited remotely to None.
  33. An information disclosure vulnerability in Windows Clustered Shared Volume can be exploited remotely to obtain sensitive information.
  34. A security feature bypass vulnerability in Windows Authentication can be exploited remotely to None.
  35. An elevation of privilege vulnerability in Storage Spaces Direct can be exploited remotely to None.
  36. A remote code execution vulnerability in Windows Address Book can be exploited remotely to execute arbitrary code.
  37. An elevation of privilege vulnerability in Windows PlayToManager can be exploited remotely to None.
  38. A remote code execution vulnerability in Point-to-Point Tunneling Protocol can be exploited remotely to execute arbitrary code.
  39. A denial of service vulnerability in Windows WLAN AutoConfig Service can be exploited remotely to cause denial of service.
  40. An elevation of privilege vulnerability in Active Directory Domain Services can be exploited remotely to None.
  41. An information disclosure vulnerability in Windows Remote Access Connection Manager can be exploited remotely to None.
  42. An information disclosure vulnerability in Windows WLAN AutoConfig Service can be exploited remotely to gain privileges.
  43. An elevation of privilege vulnerability in Tablet Windows User Interface Application Core can be exploited remotely to None.
  44. An information disclosure vulnerability in Windows Print Spooler can be exploited remotely to None.
  45. An information disclosure vulnerability in Windows Kernel can be exploited remotely to None.
Exploitation

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Affected products

Windows 10 Version 20H2 for ARM64-based Systems
Windows Server 2019 (Server Core installation)
Windows 10 Version 1809 for 32-bit Systems
Windows 10 Version 20H2 for x64-based Systems
Windows 8.1 for 32-bit systems
Windows 10 Version 21H1 for 32-bit Systems
Windows 10 Version 1909 for x64-based Systems
Windows 10 Version 1809 for x64-based Systems
Windows Server 2012 R2
Windows 10 Version 1909 for ARM64-based Systems
Windows Server 2016
Windows Server, version 20H2 (Server Core Installation)
Windows Server 2019
Windows 10 Version 21H2 for 32-bit Systems
Windows Server 2012 (Server Core installation)
Windows Server 2016 (Server Core installation)
Windows 10 Version 1909 for 32-bit Systems
Windows 10 for x64-based Systems
Windows 10 Version 21H1 for ARM64-based Systems
Windows RT 8.1
Windows Server 2022
Windows 10 Version 21H1 for x64-based Systems
Windows 10 Version 1607 for 32-bit Systems
Windows Server 2022 (Server Core installation)
Windows 10 Version 21H2 for ARM64-based Systems
Windows 11 for ARM64-based Systems
Windows 11 for x64-based Systems
Windows 10 for 32-bit Systems
Windows Server 2012
Windows 10 Version 21H2 for x64-based Systems
Windows 10 Version 1809 for ARM64-based Systems
Windows 8.1 for x64-based systems
Windows 10 Version 1607 for x64-based Systems
Windows Server 2012 R2 (Server Core installation)
Windows 10 Version 20H2 for 32-bit Systems

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2022-29137
CVE-2022-29140
CVE-2022-29106
CVE-2022-29127
CVE-2022-22019
CVE-2022-22017
CVE-2022-29104
CVE-2022-29102
CVE-2022-29151
CVE-2022-29129
CVE-2022-29122
CVE-2022-29150
CVE-2022-29132
CVE-2022-29130
CVE-2022-26927
CVE-2022-26925
CVE-2022-29105
CVE-2022-29113
CVE-2022-22011
CVE-2022-29128
CVE-2022-23279
CVE-2022-22014
CVE-2022-29133
CVE-2022-29131
CVE-2022-26936
CVE-2022-29115
CVE-2022-22012
CVE-2022-26931
CVE-2022-22013
CVE-2022-29125
CVE-2022-29139
CVE-2022-29141
CVE-2022-22713
CVE-2022-29138
CVE-2022-29112
CVE-2022-29103
CVE-2022-26937
CVE-2022-22015
CVE-2022-26933
CVE-2022-29135
CVE-2022-24466
CVE-2022-26940
CVE-2022-29134
CVE-2022-26913
CVE-2022-26938
CVE-2022-26926
CVE-2022-22016
CVE-2022-23270
CVE-2022-29142
CVE-2022-29121
CVE-2022-21972
CVE-2022-26923
CVE-2022-26930
CVE-2022-29123
CVE-2022-29120
CVE-2022-26935
CVE-2022-29126
CVE-2022-29114
CVE-2022-29116
CVE-2022-26934
CVE-2022-26932
CVE-2022-26939

Impacts
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]

PE 
[?]

SUI 
[?]
Related products
Microsoft Windows
Microsoft Windows Server
Microsoft Windows Server 2012
Microsoft Windows 8
Windows RT
Microsoft Windows 10
Microsoft Windows Server 2016
Microsoft Windows Server 2019
CVE-IDS
?
KB list

5014018
5014001
5013942
5013941
5014025
5013952
5013943
5013944
5014011
5013945
5014017
5013963

Microsoft official advisories
Microsoft Security Update Guide
Find out the statistics of the vulnerabilities spreading in your region