Microsoft’s September 2022 Patch Tuesday fixes over 60 flaws, including zero-day

Microsoft’s September 2022 Patch Tuesday fixes over 60 flaws, including zero-day

Microsoft has released its monthly batch of security updates to address more than 60 security vulnerabilities in a wide range of its software products, including a zero-day flaw actively exploited in hacker attacks.

Tracked as CVE-2022-37969, the zero-day bug has been described as privilege escalation flaw affecting the Windows Common Log File System (CLFS) Driver, which could be used by a local attacker to execute arbitrary code with SYSTEM privileges. The flaw affects Windows versions starting from Windows 7 through 11 21H2, and Windows Server 2012 - 2022 20H2.

Other security issues of note fixed with the release of the September 2022 Patch Tuesday updates include high-risk vulnerabilities impacting Microsoft ODBC Driver, Microsoft OLE DB Provider for SQL Server, Windows IKE Extension, Windows TCP/IP, Dynamics CRM, Microsoft .NET Framework, Office Visio, PowerPoint, Windows Secure Channel, Windows Kerberos, LDAP, Remote Procedure Call Runtime, Windows Fax Service, AV1 Video Extension, and other software.

Back to the list

Latest Posts

Cyber Security Week in Review: May 16, 2025

Cyber Security Week in Review: May 16, 2025

In brief: Microsoft, Fortinet, Ivanti, and Google patch zero-days, crypto exchange Coinbase reveals a data breach, and more.
16 May 2025
Russia-linked espionage operation targeting webmail servers via XSS flaws

Russia-linked espionage operation targeting webmail servers via XSS flaws

The campaign exploits XSS vulnerabilities in widely used webmail servers to steal sensitive data from high-value targets.
15 May 2025
Kosovo man extradited to US for running BlackDB.cc criminal marketplace

Kosovo man extradited to US for running BlackDB.cc criminal marketplace

If convicted on all counts, Masurica faces up to 55 years in federal prison.
14 May 2025