{"id":19581,"date":"2022-07-12T21:20:58","date_gmt":"2022-07-13T05:20:58","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/07\/12\/news-13314\/"},"modified":"2022-07-12T21:20:58","modified_gmt":"2022-07-13T05:20:58","slug":"news-13314","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/07\/12\/news-13314\/","title":{"rendered":"July Patch Tuesday is Rich in Azure, Windows Issues"},"content":{"rendered":"<p><strong>Credit to Author: Angela Gunn| Date: Wed, 13 Jul 2022 03:20:43 +0000<\/strong><\/p>\n<div class=\"entry-content lg:prose-lg mx-auto prose max-w-4xl\">\n<p><span data-contrast=\"auto\">Microsoft on Tuesday released patches for 85 vulnerabilities in six Microsoft product families. All but six of those are rated Important in severity, and once again the majority (47) affect Windows. Azure makes up the lion\u2019s share of the remainder with 34 patches in queue, with Edge, Office, Defender, and Xbox Live each receiving one update apiece. Three of the included Important-severity information-disclosure patches actually hail from third parties \u2013 two from AMD, one from HackerOne. One Important-class Elevation of Privilege issue, affecting Windows, is currently under active exploit in the wild.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\"> One advisory, with connections to Redmond&#8217;s long-awaited Windows Autopatch function,\u00a0 is also included in this month&#8217;s collection.<\/span><\/p>\n<p><span data-contrast=\"auto\">There are only four Critical-class vulnerabilities this month, all for Windows, all listed as less likely to be exploited. The sole issue identified as actually under exploit, CVE-2022-22047, affects Client\/Server Runtime Subsystem Service (CSRSS); it\u2019s described as an Important-class Elevation of Privilege issue of potentially low attack complexity, requiring low privileges and no user interaction, and affecting both client and server installations. As such, administrators should consider this issue to be worth addressing sooner rather than later.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p>The two AMD-originated patches are both connected to the chip manufacturer&#8217;s own <a href=\"https:\/\/www.amd.com\/en\/corporate\/product-security\/bulletin\/amd-sb-1037\">AMD-SB-1037<\/a> bulletin, also issued Tuesday. That bulletin addresses <a href=\"https:\/\/comsec.ethz.ch\/wp-content\/files\/retbleed_sec22.pdf\">Retbleed<\/a>, a speculative execution attack affecting certain AMD and Intel processors. Retbleed is in turn a variation on a Spectre microarchitectural timing side-channel attack. Retbleed exploits a security defense called retponline, which was developed to counter Spectre-type attacks, but which has been known to be potentially vulnerable to this sort of attack for years. (Intel, also vulnerable, is <a href=\"https:\/\/community.intel.com\/t5\/Blogs\/Products-and-Solutions\/Security\/Chips-Salsa-Episode-21-July-2022-Security-Advisories-Retbleed\/post\/1399055\">releasing<\/a> advisory information this week as well. Microsoft&#8217;s patches today do not include that information.)<\/p>\n<p><span data-contrast=\"auto\">Aside from the sheer volume of Azure patches, a few issues addressed in July stand out just because Black Hat is on the horizon. Among various researchers regularly reporting issues to Microsoft, Devcore\u2019s Cheng-Da \u201cOrange\u201d Tsai, who earlier this year disclosed the series of Exchange vulnerabilities that became ProxyLogon, is credited with three Important-severity IIS finds in this month\u2019s patch collection. He\u2019ll be speaking on destabilizing IIS\u2019 hash table at next month\u2019s conference.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><strong>By the Numbers<\/strong><\/p>\n<ul>\n<li>Total Microsoft CVEs: 82<\/li>\n<li>Total third-party CVEs also shipping in update: 3<\/li>\n<li>Publicly disclosed: 0<\/li>\n<li>Publicly exploited: 1<\/li>\n<li>Exploitation detected: 1 (both older and newer product versions)<\/li>\n<li>Exploitation more likely: 5 (both older and newer product versions)<\/li>\n<li>Severity\n<ul>\n<li>Critical: 4<\/li>\n<li>Important: 80<\/li>\n<li>Low: 1<\/li>\n<\/ul>\n<\/li>\n<li>Impact\n<ul>\n<li>Elevation of Privilege: 54<\/li>\n<li>Remote Code Execution: 12<\/li>\n<li>Information Disclosure: 9<\/li>\n<li>Information Disclosure: 9<\/li>\n<li>Tampering: 3<\/li>\n<li>Denial of Service: 2<\/li>\n<li>Spoofing: 1<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-1.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-85626\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-1.png\" alt=\"mportant-severity Elevation of Privilege issues compose the vast majority of July 2022\u2019s patches\" width=\"640\" height=\"427\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-1.png 2934w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-1.png?resize=300,200 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-1.png?resize=768,512 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-1.png?resize=1024,683 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-1.png?resize=1536,1024 1536w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-1.png?resize=2048,1365 2048w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p><em><span class=\"TextRun SCXW201438293 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW201438293 BCX0\">Figure 1: <\/span><span class=\"NormalTextRun SCXW201438293 BCX0\">Important-severity Elevation of Privilege issues <\/span><span class=\"NormalTextRun SCXW201438293 BCX0\">compose the vast majority of July\u2019s patches<\/span><\/span><span class=\"EOP SCXW201438293 BCX0\" data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/em><\/p>\n<ul>\n<li>Products\n<ul>\n<li>Microsoft Windows: 47<\/li>\n<li>Azure: 34<\/li>\n<li>Microsoft Office: 1<\/li>\n<li>Defender: 1<\/li>\n<li>Skype \/ Lync: 1<\/li>\n<li>Xbox Live: 1<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-85627\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-2.png\" alt=\"Windows makes up the majority of July\u2019s vulnerabilities, including all four of the Critical-class issues; Azure has 34, and Edge, Office, Skype \/ Lync, and Xbox have one each in July.\" width=\"640\" height=\"407\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-2.png 3071w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-2.png?resize=300,191 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-2.png?resize=768,489 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-2.png?resize=1024,652 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-2.png?resize=1536,978 1536w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-2.png?resize=2048,1304 2048w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p><i><span data-contrast=\"auto\">Figure 2: Windows makes up the majority of July\u2019s vulnerabilities, including all four of the Critical-class issues<\/span><\/i><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Notable Vulnerabilities<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Windows CSRSS Elevation of Privilege (CVE-2022-22047)<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">This is one of three elevation of privilege vulnerabilities affecting the Windows Client Server Run-Time Subsystem (CSRSS). All three are described as being of potentially low attack complexity, requiring low privileges and no user interaction and affect both client and server installations. Most importantly, it\u2019s also the only vulnerability called out as being under active exploitation as of time of release. While we have not seen any proof of concept code as of the release and it is rated as \u201cImportant\u201d, these factors make this a vulnerability that administrators should address sooner than later and best to address all three CSRSS vulnerabilities at once.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Microsoft Defender for Endpoint Tampering Vulnerability (CVE-2022-33637)<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">As a class of vulnerability, tampering is represented far more prominently than usual in July, with three issues \u2013 two affecting Windows, and one touching only Microsoft Defender for Endpoint for Linux. Successful exploitation of this vulnerability would require an attacker to authenticate to the management console appliance and to have a specific integration token.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">BitLocker Security Bypass Feature Vulnerability (CVE-2022-22048)<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">It has a maximum severity of Important and requires that an attacker have physical attack to the target machine, but this vulnerability is capable of bypassing BitLocker encryption on the machine \u2013 even if it\u2019s powered off. Both client and server Windows installations are affected.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><strong>Latest Servicing Stack Updates (Advisory ADV990001)<\/strong><\/p>\n<p>A servicing-stack update makes changes to the component that installs Windows updates as well as to the CBS (component-based servicing stack), another crucial underpinning of the operating system. Generally, such updates are issued in response to a newly discovered issue or vulnerability, though in this case the more likely scenario involves the release of Microsoft&#8217;s Windows Autopatch feature. Since the ability to install other security patches may be predicated on whether the servicing stack is up to date,\u00a0 we suggest that administrators make <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/ADV990001\">ADV990001<\/a> a priority. (Microsoft offers an overview of <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/deployment\/update\/servicing-stack-updates\">servicing stack updates<\/a> for those unfamiliar with this infrequently updated component.)<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-3.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-85628\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-3.png\" alt=\"As of July 2022 Microsoft has issued patches for just over 200 EoP issues, and just under 200 RCE; nothing else comes close.\" width=\"640\" height=\"426\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-3.png 2934w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-3.png?resize=300,200 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-3.png?resize=768,512 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-3.png?resize=1024,682 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-3.png?resize=1536,1023 1536w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/figure-3.png?resize=2048,1365 2048w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p><em><span class=\"TextRun SCXW64388034 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW64388034 BCX0\">Figure 3: July\u2019s preponderance of Elevation of Privilege <\/span><span class=\"NormalTextRun SCXW64388034 BCX0\">issues <\/span><span class=\"NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW64388034 BCX0\">bring<\/span><span class=\"NormalTextRun SCXW64388034 BCX0\"> 2022\u2019s <\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW64388034 BCX0\">EoP<\/span><span class=\"NormalTextRun SCXW64388034 BCX0\"> count slightly ahead of the count for Remote Code Execution <\/span><span class=\"NormalTextRun SCXW64388034 BCX0\">vulnerabilities<\/span><\/span><span class=\"EOP SCXW64388034 BCX0\" data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/em><\/p>\n<p><b><span data-contrast=\"auto\">Sophos protection<\/span><\/b><span data-contrast=\"none\">\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span class=\"TextRun SCXW147864987 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW147864987 BCX0\">As you can every month, if you don\u2019t want to wait for your system to pull down the updates itself, you can download them manually from the Windows Update Catalog website<\/span><span class=\"NormalTextRun SCXW147864987 BCX0\">.<\/span><span class=\"NormalTextRun SCXW147864987 BCX0\"> Run the winver.exe tool to determine which build of Windows 10 or 11 you\u2019re running, then download the Cumulative Update package for your <\/span><span class=\"NormalTextRun AdvancedProofingIssueV2Themed SCXW147864987 BCX0\">particular system\u2019s<\/span><span class=\"NormalTextRun SCXW147864987 BCX0\"> architecture and build number.<\/span><\/span><span class=\"EOP SCXW147864987 BCX0\" data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.sophos.com\/en-us\/2022\/07\/12\/july-patch-tuesday-is-rich-in-azure-windows-issues\/\" target=\"bwo\" >http:\/\/feeds.feedburner.com\/sophos\/dgdY<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/shutterstock_2107294592.jpg\"\/><\/p>\n<p><strong>Credit to Author: Angela Gunn| Date: Wed, 13 Jul 2022 03:20:43 +0000<\/strong><\/p>\n<p>Windows-facing issues make up the bulk of the 85 CVEs addressed, with one vulnerability under active exploit in the wild<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10377],"tags":[26944,19245,18513,16771],"class_list":["post-19581","post","type-post","status-publish","format-standard","hentry","category-security","category-sophos","tag-2022-07","tag-patch-tuesday","tag-sophoslabs-uncut","tag-threat-research"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19581","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19581"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19581\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19581"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19581"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19581"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}