Detection and Response

Patch Tuesday - February 2022

|Last updated on Feb 8, 2022|1 min read
LinkedInFacebookX
Patch Tuesday - February 2022

Today’s fixes from Microsoft are relatively light as far as Patch Tuesdays go. This is the first month in possibly forever where no vulnerabilities are considered Critical. A total of 70 CVEs were fixed today (including 22 that affect the Chromium browser engine, which is used by Edge).

Although 16 of this month’s vulnerabilities allow remote code execution (RCE), none carry a CVSS base score higher than 8.8. Only one vulnerability was publicly disclosed before today: CVE-2022-21989, an elevation of privilege vulnerability in the Windows Kernel. None of this month’s vulnerabilities have yet been seen exploited in the wild.

Despite the lack of Critical fixes, it’s worth remembering that attackers love to use elevation of privilege vulnerabilities, of which there are 18 this month. RCE vulnerabilities are also important to patch, even if they may not be considered “wormable.” In terms of prioritization, defenders should first focus on patching server systems. SharePoint has RCE (CVE-2022-22005), Security Feature Bypass (CVE-2022-21968), and Spoofing (CVE-2022-21987) vulnerabilities getting fixed today. CVE-2022-21984 is an RCE affecting DNS Server. Microsoft Dynamics administrators should also be aware that there are six CVEs being patched, including 2 RCEs, 3 allowing elevation of privilege, and a spoofing vulnerability.

On the client side, CVE-2022-22003 and CVE-2022-22004 are RCEs affecting Microsoft Office. Although this requires a local user to open a malicious file, these sorts of social engineering attacks are common and can be very effective. Updates should be rolled out to end users as soon as reasonably practicable.

Summary charts

2022-02-vuln_count_severity.png2022-02-vuln_count_impact.png2022-02-cvssv3_hist.png2022-02-vuln_count_component.png

Summary tables

Azure Vulnerabilities

CVETitleExploitedPublicly DisclosedCVSSv3 Base ScoreHas FAQ?
CVE-2022-23256Azure Data Explorer Spoofing VulnerabilityNoNo8.1Yes

Browser Vulnerabilities

CVETitleExploitedPublicly DisclosedCVSSv3 Base ScoreHas FAQ?
CVE-2022-23261Microsoft Edge (Chromium-based) Tampering VulnerabilityNoNo5.3Yes
CVE-2022-23263Microsoft Edge (Chromium-based) Elevation of Privilege VulnerabilityNoNo7.7Yes
CVE-2022-23262Microsoft Edge (Chromium-based) Elevation of Privilege VulnerabilityNoNo6.3Yes
CVE-2022-0470Chromium: CVE-2022-0470 Out of bounds memory access in V8NoNoN/AYes
CVE-2022-0469Chromium: CVE-2022-0469 Use after free in CastNoNoN/AYes
CVE-2022-0468Chromium: CVE-2022-0468 Use after free in PaymentsNoNoN/AYes
CVE-2022-0467Chromium: CVE-2022-0467 Inappropriate implementation in Pointer LockNoNoN/AYes
CVE-2022-0466Chromium: CVE-2022-0466 Inappropriate implementation in Extensions PlatformNoNoN/AYes
CVE-2022-0465Chromium: CVE-2022-0465 Use after free in ExtensionsNoNoN/AYes
CVE-2022-0464Chromium: CVE-2022-0464 Use after free in AccessibilityNoNoN/AYes
CVE-2022-0463Chromium: CVE-2022-0463 Use after free in AccessibilityNoNoN/AYes
CVE-2022-0462Chromium: CVE-2022-0462 Inappropriate implementation in ScrollNoNoN/AYes
CVE-2022-0461Chromium: CVE-2022-0461 Policy bypass in COOPNoNoN/AYes
CVE-2022-0460Chromium: CVE-2022-0460 Use after free in Window DialogNoNoN/AYes
CVE-2022-0459Chromium: CVE-2022-0459 Use after free in Screen CaptureNoNoN/AYes
CVE-2022-0458Chromium: CVE-2022-0458 Use after free in Thumbnail Tab StripNoNoN/AYes
CVE-2022-0457Chromium: CVE-2022-0457 Type Confusion in V8NoNoN/AYes
CVE-2022-0456Chromium: CVE-2022-0456 Use after free in Web SearchNoNoN/AYes
CVE-2022-0455Chromium: CVE-2022-0455 Inappropriate implementation in Full Screen ModeNoNoN/AYes
CVE-2022-0454Chromium: CVE-2022-0454 Heap buffer overflow in ANGLENoNoN/AYes
CVE-2022-0453Chromium: CVE-2022-0453 Use after free in Reader ModeNoNoN/AYes
CVE-2022-0452Chromium: CVE-2022-0452 Use after free in Safe BrowsingNoNoN/AYes

Developer Tools Vulnerabilities

CVETitleExploitedPublicly DisclosedCVSSv3 Base ScoreHas FAQ?
CVE-2022-21991Visual Studio Code Remote Development Extension Remote Code Execution VulnerabilityNoNo8.1Yes
CVE-2022-21986.NET Denial of Service VulnerabilityNoNo7.5Yes

ESU Windows Vulnerabilities

CVETitleExploitedPublicly DisclosedCVSSv3 Base ScoreHas FAQ?
CVE-2022-21985Windows Remote Access Connection Manager Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2022-22718Windows Print Spooler Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2022-21999Windows Print Spooler Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2022-21997Windows Print Spooler Elevation of Privilege VulnerabilityNoNo7.1Yes
CVE-2022-22717Windows Print Spooler Elevation of Privilege VulnerabilityNoNo7Yes
CVE-2022-21989Windows Kernel Elevation of Privilege VulnerabilityNoYes7.8Yes
CVE-2022-21998Windows Common Log File System Driver Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2022-21981Windows Common Log File System Driver Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2022-22000Windows Common Log File System Driver Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2022-22710Windows Common Log File System Driver Denial of Service VulnerabilityNoNo5.5No

Microsoft Dynamics Vulnerabilities

CVETitleExploitedPublicly DisclosedCVSSv3 Base ScoreHas FAQ?
CVE-2022-23269Microsoft Dynamics GP Spoofing VulnerabilityNoNo6.9Yes
CVE-2022-23274Microsoft Dynamics GP Remote Code Execution VulnerabilityNoNo8.3Yes
CVE-2022-23272Microsoft Dynamics GP Elevation Of Privilege VulnerabilityNoNo8.1Yes
CVE-2022-23273Microsoft Dynamics GP Elevation Of Privilege VulnerabilityNoNo7.1No
CVE-2022-23271Microsoft Dynamics GP Elevation Of Privilege VulnerabilityNoNo6.5No
CVE-2022-21957Microsoft Dynamics 365 (on-premises) Remote Code Execution VulnerabilityNoNo7.2No

Microsoft Office Vulnerabilities

CVETitleExploitedPublicly DisclosedCVSSv3 Base ScoreHas FAQ?
CVE-2022-21965Microsoft Teams Denial of Service VulnerabilityNoNo7.5Yes
CVE-2022-21987Microsoft SharePoint Server Spoofing VulnerabilityNoNo8Yes
CVE-2022-21968Microsoft SharePoint Server Security Feature BypassVulnerabilityNoNo4.3Yes
CVE-2022-22005Microsoft SharePoint Server Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2022-23280Microsoft Outlook for Mac Security Feature Bypass VulnerabilityNoNo5.3Yes
CVE-2022-23255Microsoft OneDrive for Android Security Feature Bypass VulnerabilityNoNo5.9Yes
CVE-2022-21988Microsoft Office Visio Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-23252Microsoft Office Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2022-22003Microsoft Office Graphics Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-22004Microsoft Office ClickToRun Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-22716Microsoft Excel Information Disclosure VulnerabilityNoNo5.5Yes

SQL Server Vulnerabilities

CVETitleExploitedPublicly DisclosedCVSSv3 Base ScoreHas FAQ?
CVE-2022-23276SQL Server for Linux Containers Elevation of Privilege VulnerabilityNoNo7.8Yes
CVE-2022-23254Microsoft Power BI Elevation of Privilege VulnerabilityNoNo4.9Yes

Windows Vulnerabilities

CVETitleExploitedPublicly DisclosedCVSSv3 Base ScoreHas FAQ?
CVE-2022-22002Windows User Account Profile Picture Denial of Service VulnerabilityNoNo5.5No
CVE-2022-21993Windows Services for NFS ONCRPC XDR Driver Information Disclosure VulnerabilityNoNo7.5Yes
CVE-2022-21971Windows Runtime Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-22001Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2022-21992Windows Mobile Device Management Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-21995Windows Hyper-V Remote Code Execution VulnerabilityNoNo7.9Yes
CVE-2022-22712Windows Hyper-V Denial of Service VulnerabilityNoNo5.6Yes
CVE-2022-21994Windows DWM Core Library Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2022-21984Windows DNS Server Remote Code Execution VulnerabilityNoNo8.8No
CVE-2022-21996Win32k Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2022-22709VP9 Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-21974Roaming Security Rights Management Services Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-22715Named Pipe File System Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2022-21844HEVC Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-21926HEVC Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-21927HEVC Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes

NEVER MISS A BLOG

Get the latest stories, expertise, and news about security today.

Subscribe

Related blog posts