Exposure Management

Patch Tuesday - June 2022

|Last updated on Jun 15, 2022|1 min read
LinkedInFacebookX
Patch Tuesday - June 2022

June's Patch Tuesday sees Microsoft releasing fixes for over 60 CVEs. Top of mind for many administrators this month is CVE-2022-30190, also known as Follina, which was observed being exploited in the wild at the end of May. Microsoft provided mitigation instructions (disabling the MSDT URL protocol via the registry), but actual patches were not available until today’s cumulative Windows Updates. Even if the mitigation was previously applied, installing the updates is highly recommended.

None of the other CVEs being addressed this month have been previously disclosed or seen exploited yet. However, it won’t be long before attackers start looking at CVE-2022-30136, a critical remote code execution (RCE) vulnerability affecting the Windows Network File System (NFS). Last month, Microsoft fixed a similar vulnerability (CVE-2022-26937) affecting NFS v2.0 and v3.0. CVE-2022-30136, on the other hand, is only exploitable in NFS v4.1. Microsoft has provided mitigation guidance to disable NFS v4.1, which should only be done if the May updates fixing previous NFS versions have been applied. Again, even if the mitigation has been put into place, best to patch sooner rather than later.

Also reminiscent of last month is CVE-2022-30139, a critical RCE in LDAP carrying a CVSSv3 base score of 7.1, which again is only exploitable if the MaxReceiveBuffer LDAP policy value is set higher than the default. Rounding out the critical RCEs for June is CVE-2022-30163, which could allow a malicious application running on a Hyper-V guest to execute code on the host OS.

The other big news this month is the end of support for Internet Explorer 11 (IE11) on Windows 10 Semi-Annual Channels and Windows 10 IoT Semi-Annual Channels, as Microsoft encourages users to adopt the Chromium-based Edge browser (which saw fixes for 5 CVEs this month). Internet Explorer 11 on other versions of Windows should continue receiving security updates and technical support based on the OS support lifecycle, so this is only the beginning of the end for the legacy browser.

Summary charts

2022-06-vuln_count_severity.png2022-06-vuln_count_impact.png2022-06-cvssv3_hist.png2022-06-vuln_count_component.png

Summary tables

Apps vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-30168Microsoft Photos App Remote Code Execution VulnerabilityNoNo7.8Yes

Azure vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-30137Azure Service Fabric Container Elevation of Privilege VulnerabilityNoNo6.7Yes
CVE-2022-30177Azure RTOS GUIX Studio Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-30178Azure RTOS GUIX Studio Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-30179Azure RTOS GUIX Studio Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-30180Azure RTOS GUIX Studio Information Disclosure VulnerabilityNoNo7.8Yes

Azure System Center vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-29149Azure Open Management Infrastructure (OMI) Elevation of Privilege VulnerabilityNoNo7.8Yes

Browser vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-22021Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityNoNo8.3Yes
CVE-2022-2011Chromium: CVE-2022-2011 Use after free in ANGLENoNoN/AYes
CVE-2022-2010Chromium: CVE-2022-2010 Out of bounds read in compositingNoNoN/AYes
CVE-2022-2008Chromium: CVE-2022-2008 Out of bounds memory access in WebGLNoNoN/AYes
CVE-2022-2007Chromium: CVE-2022-2007 Use after free in WebGPUNoNoN/AYes

Developer Tools vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-30184.NET and Visual Studio Information Disclosure VulnerabilityNoNo5.5Yes

ESU Windows vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-30140Windows iSCSI Discovery Service Remote Code Execution VulnerabilityNoNo7.1Yes
CVE-2022-30152Windows Network Address Translation (NAT) Denial of Service VulnerabilityNoNo7.5No
CVE-2022-30135Windows Media Center Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2022-30153Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2022-30161Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2022-30141Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityNoNo8.1Yes
CVE-2022-30143Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityNoNo7.5Yes
CVE-2022-30149Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityNoNo7.5Yes
CVE-2022-30146Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityNoNo7.5Yes
CVE-2022-30155Windows Kernel Denial of Service VulnerabilityNoNo5.5Yes
CVE-2022-30147Windows Installer Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2022-30163Windows Hyper-V Remote Code Execution VulnerabilityNoNo8.5Yes
CVE-2022-30142Windows File History Remote Code Execution VulnerabilityNoNo7.1Yes
CVE-2022-30151Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityNoNo7Yes
CVE-2022-30160Windows Advanced Local Procedure Call Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2022-30166Local Security Authority Subsystem Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2022-21166Intel: CVE-2022-21166 Device Register Partial Write (DRPW)NoNoN/AYes
CVE-2022-21127Intel: CVE-2022-21127 Special Register Buffer Data Sampling Update (SRBDS Update)NoNoN/AYes
CVE-2022-21125Intel: CVE-2022-21125 Shared Buffers Data Sampling (SBDS)NoNoN/AYes
CVE-2022-21123Intel: CVE-2022-21123 Shared Buffers Data Read (SBDR)NoNoN/AYes

Microsoft Office vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-30157Microsoft SharePoint Server Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2022-30158Microsoft SharePoint Server Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2022-30174Microsoft Office Remote Code Execution VulnerabilityNoNo7.4Yes
CVE-2022-30159Microsoft Office Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2022-30171Microsoft Office Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2022-30172Microsoft Office Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2022-30173Microsoft Excel Remote Code Execution VulnerabilityNoNo7.8Yes

SQL Server vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-29143Microsoft SQL Server Remote Code Execution VulnerabilityNoNo7.5Yes

Windows vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-32230Windows SMB Denial of Service VulnerabilityNoNoN/AYes
CVE-2022-30136Windows Network File System Remote Code Execution VulnerabilityNoNo9.8Yes
CVE-2022-30139Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityNoNo7.5Yes
CVE-2022-30162Windows Kernel Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2022-30165Windows Kerberos Elevation of Privilege VulnerabilityNoNo8.8Yes
CVE-2022-30145Windows Encrypting File System (EFS) Remote Code Execution VulnerabilityNoNo7.5Yes
CVE-2022-30148Windows Desired State Configuration (DSC) Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2022-30150Windows Defender Remote Credential Guard Elevation of Privilege VulnerabilityNoNo7.5Yes
CVE-2022-30132Windows Container Manager Service Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2022-30131Windows Container Isolation FS Filter Driver Elevation of Privilege VulnerabilityNoNo7.8No
CVE-2022-30189Windows Autopilot Device Management and Enrollment Client Spoofing VulnerabilityNoNo6.5Yes
CVE-2022-30154Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege VulnerabilityNoNo5.3Yes
CVE-2022-30164Kerberos AppContainer Security Feature Bypass VulnerabilityNoNo8.4Yes
CVE-2022-29111HEVC Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-22018HEVC Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-30188HEVC Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-29119HEVC Video Extensions Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-30167AV1 Video Extension Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-30193AV1 Video Extension Remote Code Execution VulnerabilityNoNo7.8Yes

NEVER MISS A BLOG

Get the latest stories, expertise, and news about security today.

Subscribe

Additional reading:

Related blog posts