当前位置:网站首页>2022-02 Microsoft vulnerability notification
2022-02 Microsoft vulnerability notification
2022-06-29 05:36:00 【User 6477171】
Microsoft officially released 2022 year 02 Monthly security update . This month's update announced 70 A loophole , contain 17 A privilege escalation vulnerability 、16 Remote Code Execution Vulnerability 、6 An information leak 、5 A denial of service vulnerability 、3 An identity counterfeiting vulnerability 、3 A security feature bypasses vulnerabilities and 1 A tampering vulnerability , among 50 The vulnerability level is “Important”( serious ). Users are advised to use the tinder safety software in time ( personal / Enterprises )【 Bug repair 】 Feature update patch .
01
Involved components
- Azure Data Explorer
- Kestrel Web Server
- Microsoft Dynamics
- Microsoft Dynamics GP
- Microsoft Edge (Chromium-based)
- Microsoft Office
- Microsoft Office Excel
- Microsoft Office Outlook
- Microsoft Office SharePoint
- Microsoft Office Visio
- Microsoft OneDrive
- Microsoft Teams
- Microsoft Windows Codecs Library
- Power BI
- Roaming Security Rights Management Services
- Role: DNS Server
- Role: Windows Hyper-V
- SQL Server
- Visual Studio Code
- Windows Common Log File System Driver
- Windows DWM Core Library
- Windows Kernel
- Windows Kernel-Mode Drivers
- Windows Named Pipe File System
- Windows Print Spooler Components
- Windows Remote Access Connection Manager
- Windows Remote Procedure Call Runtime
- Windows User Account Profile
- Windows Win32K
( Slide down to view )
02
The following vulnerabilities require special attention
Windows Kernel privilege escalation vulnerability
CVE-2022-21989
Severity level : serious CVSS:7.8
Utilized level : May be used
An attacker who successfully exploits this vulnerability can elevate privileges and execute malicious programs or access resources . The vulnerability has been publicly disclosed , No wild use has been found yet .
Microsoft OfficeGraphics Remote code execution vulnerability
CVE-2022-22003
Severity level : serious CVSS:7.8
Utilized level : May be used
After user interaction triggers the vulnerability , An attacker can exploit this vulnerability to conduct a local attack on the victim's computer . The preview pane is not the medium of this vulnerability , Therefore, the vulnerability will not be triggered .
Microsoft Office ClickToRun Remote code execution vulnerability
CVE-2022-22004
Severity level : serious CVSS:7.8
Utilized level : May be used
The vulnerability and CVE-2022-22003 be similar , Require user interaction to trigger vulnerability . An attacker can exploit this vulnerability to conduct a local attack on the victim's computer .
Windows DNS Server Remote code execution vulnerability
CVE-2022-21984
Severity level : serious CVSS:8.8
Utilized level : May be used
The flaw in the DNS The configuration is easy to be exploited by attackers when dynamic updates are enabled . An attacker who successfully exploits this vulnerability can execute arbitrary code on the victim's computer .
03
Repair suggestions
1、 Through the tinder Personal Edition / Enterprise Edition 【 Bug repair 】 Function fix vulnerability .
2、 Download the official patch from Microsoft
https://msrc.microsoft.com/update-guide
Complete Microsoft notice :
https://msrc.microsoft.com/update-guide/releaseNote/2022-Feb
边栏推荐
- 没遇到过这三个问题都不好意思说用过Redis
- 嵌入式RTOS
- 笔记本访问台式机的共享磁盘
- Use VS to create a static link library Lib and use
- Matlab直接求贝塞尔函数的导函数
- Top ten Devops best practices worthy of attention in 2022
- 2022 recommended tire industry research report industry development prospect market analysis white paper
- Network device setting / canceling console port login separate password
- ES6 Modularization: export /import
- Distributed transaction Seata
猜你喜欢

5,10-di (4-aminophenyl) - 15,20-diphenylporphyrin (cis-dadph2) /5,15-di (4-aminophenyl) - 10,20-diphenylporphyrin (trans-dadph2) / (tri-apph2) supplied by Qiyue

Test content

Tcapulusdb Jun · industry news collection (V)

Open a new ecological posture | use WordPress remote attachment to store to Cos

Analysis report on the investment market of the development planning prospect of the recommended rare earth industry research industry in 2022 (the attachment is a link to the online disk, and the rep

Openfpga wishes you a happy Lantern Festival!

HTTP Caching Protocol practice

Manual (functional) test 1

Research Report on recommended specialized, special and new industries in 2022 industry development prospect and market investment analysis (the attachment is a link to the online disk, and the report

PCI Verilog IP
随机推荐
C語言用 printf 打印 《愛心》《火星撞地球》等,不斷更新
QT precautions and RCC download address
Le langage C imprime "Love", "Mars hit Earth" et ainsi de suite en utilisant printf, qui est constamment mis à jour
Mvcc principle in MySQL
HTTP Caching Protocol practice
patent filter
證券開戶安全麼,有沒有什麼危險呢
Research on heuristic intelligent task scheduling
Blip: conduct multimodal pre training with cleaner and more diverse data, and the performance exceeds clip! Open source code
2022 recommended RCEP regional comprehensive economic partnership agreement market quotation Investment Analysis Industry Research Report (the attachment is a link to the online disk, and the report i
Analysis report on the investment market of the development planning prospect of the recommended wind power industry research industry in 2022 (the attachment is a link to the network disk, and the re
To learn more about Yibo Hongmeng development
Summary of redis basic knowledge points
Openfpga wishes you a happy Lantern Festival!
Difference between parametric continuity and geometric continuity
IDENTITY
使用VS创建静态链接库.lib并使用
Test content
D Author: import C programming in D
Signal slot mechanism