14 September 2022

Microsoft’s September 2022 Patch Tuesday fixes over 60 flaws, including zero-day


Microsoft’s September 2022 Patch Tuesday fixes over 60 flaws, including zero-day

Microsoft has released its monthly batch of security updates to address more than 60 security vulnerabilities in a wide range of its software products, including a zero-day flaw actively exploited in hacker attacks.

Tracked as CVE-2022-37969, the zero-day bug has been described as privilege escalation flaw affecting the Windows Common Log File System (CLFS) Driver, which could be used by a local attacker to execute arbitrary code with SYSTEM privileges. The flaw affects Windows versions starting from Windows 7 through 11 21H2, and Windows Server 2012 - 2022 20H2.

Other security issues of note fixed with the release of the September 2022 Patch Tuesday updates include high-risk vulnerabilities impacting Microsoft ODBC Driver, Microsoft OLE DB Provider for SQL Server, Windows IKE Extension, Windows TCP/IP, Dynamics CRM, Microsoft .NET Framework, Office Visio, PowerPoint, Windows Secure Channel, Windows Kerberos, LDAP, Remote Procedure Call Runtime, Windows Fax Service, AV1 Video Extension, and other software.

Back to the list

Latest Posts

REvil hacker sentenced to 13 years for $700M ransomware spree

REvil hacker sentenced to 13 years for $700M ransomware spree

In addition to his prison sentence, Vasinskyi was ordered to pay over $16 million in restitution.
2 May 2024
Dropbox says hackers breached its Sign eSignature platform and stole sensitive data

Dropbox says hackers breached its Sign eSignature platform and stole sensitive data

The attackers accessed authentication tokens, MFA keys, hashed passwords, and customer info.
2 May 2024
New Cuttlefish malware steals credentials from SOHO routers

New Cuttlefish malware steals credentials from SOHO routers

Cuttlefish implements the functionality that allows it to execute HTTP and DNS hijacking.
1 May 2024