Searching
..

Click anywhere to stop

KLA20001
Multiple vulnerabilities in Microsoft Products (ESU)

Updated: 02/02/2024
Detect date
?
10/11/2022
Severity
?
Critical
Description

Multiple vulnerabilities were found in Microsoft Products (Extended Security Update). Malicious users can exploit these vulnerabilities to gain privileges, spoof user interface, obtain sensitive information, bypass security restrictions, execute arbitrary code, cause denial of service.

Below is a complete list of vulnerabilities:

  1. An elevation of privilege vulnerability in Windows COM+ Event System Service can be exploited remotely to gain privileges.
  2. An elevation of privilege vulnerability in Windows ALPC can be exploited remotely to gain privileges.
  3. An elevation of privilege vulnerability in Windows Group Policy Preference Client can be exploited remotely to gain privileges.
  4. A spoofing vulnerability in Windows CryptoAPI can be exploited remotely to spoof user interface.
  5. An information disclosure vulnerability in Windows Graphics Component can be exploited remotely to obtain sensitive information.
  6. An elevation of privilege vulnerability in Windows Group Policy can be exploited remotely to gain privileges.
  7. A security feature bypass vulnerability in Windows Portable Device Enumerator Service can be exploited remotely to bypass security restrictions.
  8. An elevation of privilege vulnerability in Windows Graphics Component can be exploited remotely to gain privileges.
  9. An elevation of privilege vulnerability in Active Directory Certificate Services can be exploited remotely to gain privileges.
  10. An elevation of privilege vulnerability in Active Directory Domain Services can be exploited remotely to gain privileges.
  11. A remote code execution vulnerability in Windows Point-to-Point Tunneling Protocol can be exploited remotely to execute arbitrary code.
  12. A remote code execution vulnerability in Windows CD-ROM File System Driver can be exploited remotely to execute arbitrary code.
  13. A denial of service vulnerability in Windows Event Logging Service can be exploited remotely to cause denial of service.
  14. A remote code execution vulnerability in Microsoft ODBC Driver can be exploited remotely to execute arbitrary code.
  15. An elevation of privilege vulnerability in Windows Kernel can be exploited remotely to gain privileges.
  16. A remote code execution vulnerability in Microsoft WDAC OLE DB provider for SQL Server can be exploited remotely to execute arbitrary code.
  17. A remote code execution vulnerability in Windows GDI+ can be exploited remotely to execute arbitrary code.
  18. An information disclosure vulnerability in Windows Security Support Provider Interface can be exploited remotely to obtain sensitive information.
  19. An information disclosure vulnerability in Windows DHCP Client can be exploited remotely to obtain sensitive information.
  20. A denial of service vulnerability in Windows Secure Channel can be exploited remotely to cause denial of service.
  21. A denial of service vulnerability in Windows TCP/IP Driver can be exploited remotely to cause denial of service.
  22. An elevation of privilege vulnerability in Windows Workstation Service can be exploited remotely to gain privileges.
  23. A denial of service vulnerability in Local Security Authority Subsystem Service (LSASS) can be exploited remotely to cause denial of service.
  24. An information disclosure vulnerability in Windows Server Remotely Accessible Registry Keys can be exploited remotely to obtain sensitive information.
  25. An elevation of privilege vulnerability in Windows Win32k can be exploited remotely to gain privileges.
  26. An elevation of privilege vulnerability in Windows Client Server Run-time Subsystem (CSRSS) can be exploited remotely to gain privileges.
  27. A spoofing vulnerability in Windows NTLM can be exploited remotely to spoof user interface.
  28. A security feature bypass vulnerability in Windows Active Directory Certificate Services can be exploited remotely to bypass security restrictions.
Exploitation

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Affected products

Windows 7 for 32-bit Systems Service Pack 1
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 for x64-based Systems Service Pack 2

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2022-41033
CVE-2022-38029
CVE-2022-37994
CVE-2022-34689
CVE-2022-37985
CVE-2022-37975
CVE-2022-37999
CVE-2022-38032
CVE-2022-38051
CVE-2022-37976
CVE-2022-38042
CVE-2022-38047
CVE-2022-38044
CVE-2022-37981
CVE-2022-24504
CVE-2022-38040
CVE-2022-33634
CVE-2022-37990
CVE-2022-37982
CVE-2022-37997
CVE-2022-33635
CVE-2022-22035
CVE-2022-38038
CVE-2022-38043
CVE-2022-37988
CVE-2022-37991
CVE-2022-37993
CVE-2022-38026
CVE-2022-38041
CVE-2022-30198
CVE-2022-33645
CVE-2022-38034
CVE-2022-37977
CVE-2022-38033
CVE-2022-38022
CVE-2022-37986
CVE-2022-38037
CVE-2022-41081
CVE-2022-37987
CVE-2022-38031
CVE-2022-38000
CVE-2022-35770
CVE-2022-37989
CVE-2022-37978

Impacts
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]

PE 
[?]

SUI 
[?]
Related products
Microsoft Windows
Microsoft Windows Server
Microsoft Windows 7
Microsoft Windows Server 2008
CVE-IDS
?
CVE-2022-380297.0High
CVE-2022-346897.5Critical
CVE-2022-379855.5High
CVE-2022-379758.8Critical
CVE-2022-380427.1High
CVE-2022-379814.3Warning
CVE-2022-245048.1Critical
CVE-2022-336348.1Critical
CVE-2022-379907.8Critical
CVE-2022-380387.8Critical
CVE-2022-379917.8Critical
CVE-2022-379937.8Critical
CVE-2022-380417.5Critical
CVE-2022-336457.5Critical
CVE-2022-380348.8Critical
CVE-2022-379776.5High
CVE-2022-380336.5High
CVE-2022-380377.8Critical
CVE-2022-380008.1Critical
CVE-2022-379897.8Critical
CVE-2022-379787.5Critical
CVE-2022-410337.8Critical
CVE-2022-379947.8Critical
CVE-2022-379997.8Critical
CVE-2022-380326.6High
CVE-2022-380517.8Critical
CVE-2022-379768.8Critical
CVE-2022-380478.1Critical
CVE-2022-380447.8Critical
CVE-2022-380408.8Critical
CVE-2022-379828.8Critical
CVE-2022-379977.8Critical
CVE-2022-336357.8Critical
CVE-2022-220358.1Critical
CVE-2022-380435.5High
CVE-2022-379887.8Critical
CVE-2022-380265.5High
CVE-2022-301988.1Critical
CVE-2022-380223.3Warning
CVE-2022-379867.8Critical
CVE-2022-410818.1Critical
CVE-2022-379877.8Critical
CVE-2022-380318.8Critical
CVE-2022-357706.5High
KB list

5016622
5016686
5016669
5016679
5016676
5018446
5018479
5018450
5018454

Microsoft official advisories
Microsoft Security Update Guide
Find out the statistics of the vulnerabilities spreading in your region