Skip to content
NGTEdu Logo

NGTEdu

A PRODUCT OF NGTECH.CO.IN

NGTEdu Logo

NGTEdu

  • Home
  • Cyber Attacks
  • Malware
  • Vulnerabilities
  • Data Breach
  • Home
  • Cyber Attacks
  • VERT Threat Alert: June 2022 Patch Tuesday Analysis
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

VERT Threat Alert: June 2022 Patch Tuesday Analysis

4 years ago Tyler Reguly
VERT Threat Alert: May 2021 Patch Tuesday Analysis

Today’s VERT Alert addresses Microsoft’s June 2022 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-1007 on Wednesday, June 15th.

In-The-Wild & Disclosed CVEs

None of the vulnerabilities patched this month have been exploited in-the-wild or publicly disclosed according to Microsoft. However, Microsoft did update last month’s security guidance related to the Follina vulnerability (CVE-2022-30190) and a patch has now been released. A write-up from May 29 can be read here and Microsoft’s MSRC response can be found here.

CVE Breakdown by Tag

While historical Microsoft Security Bulletin groupings are gone, Microsoft vulnerabilities are tagged with an identifier. This list provides a breakdown of the CVEs on a per tag basis. Vulnerabilities are also colour coded to aid with identifying key issues.

  • Traditional Software
  • Mobile Software
  • Cloud or Cloud Adjacent
  • Vulnerabilities that are being exploited or that have been disclosed will be highlighted.
Tag CVE Count CVEs
Azure Service Fabric Container 1 CVE-2022-30137
Windows Container Isolation FS Filter Driver 1 CVE-2022-30131
Windows Media 1 CVE-2022-30135
Windows Installer 1 CVE-2022-30147
Windows Network File System 1 CVE-2022-30136
Windows PowerShell 1 CVE-2022-30148
Microsoft Office SharePoint 2 CVE-2022-30157, CVE-2022-30158
Windows iSCSI 1 CVE-2022-30140
Microsoft Windows Codecs Library 6 CVE-2022-29111, CVE-2022-22018, CVE-2022-30167, CVE-2022-30188, CVE-2022-29119, CVE-2022-30193
SQL Server 1 CVE-2022-29143
Microsoft Office Excel 1 CVE-2022-30173
Windows Ancillary Function Driver for WinSock 1 CVE-2022-30151
Windows Kernel 2 CVE-2022-30155, CVE-2022-30162
Windows Local Security Authority Subsystem Service 1 CVE-2022-30166
Microsoft Office 4 CVE-2022-30159, CVE-2022-30171, CVE-2022-30172, CVE-2022-30174
Windows Defender 1 CVE-2022-30150
Intel 4 CVE-2022-21166, CVE-2022-21127, CVE-2022-21123, CVE-2022-21125
Windows Network Address Translation (NAT) 1 CVE-2022-30152
Remote Volume Shadow Copy Service (RVSS) 1 CVE-2022-30154
Windows File History Service 1 CVE-2022-30142
Windows Autopilot 1 CVE-2022-30189
.NET and Visual Studio 1 CVE-2022-30184
Azure OMI 1 CVE-2022-29149
Windows Kerberos 2 CVE-2022-30164, CVE-2022-30165
Windows Encrypting File System (EFS) 1 CVE-2022-30145
Windows Container Manager Service 1 CVE-2022-30132
Azure Real Time Operating System 4 CVE-2022-30177, CVE-2022-30178, CVE-2022-30179, CVE-2022-30180
Role: Windows Hyper-V 1 CVE-2022-30163
Microsoft Edge (Chromium-based) 5 CVE-2022-22021, CVE-2022-2007, CVE-2022-2008, CVE-2022-2010, CVE-2022-2011
Microsoft Windows ALPC 1 CVE-2022-30160
Windows LDAP – Lightweight Directory Access Protocol 7 CVE-2022-30141, CVE-2022-30143, CVE-2022-30149, CVE-2022-30153, CVE-2022-30161, CVE-2022-30139, CVE-2022-30146
Windows SMB 1 CVE-2022-32230
Windows App Store 1 CVE-2022-30168

Other Information

In addition to the Microsoft vulnerabilities included in the June Security Guidance, an advisory was also released today.

Microsoft Guidance on Intel Processor MMIO Stale Data Vulnerabilities [ADV220002]

Four of the vulnerabilities patched by Microsoft today are tied to INTEL-SA-000615, an Intel advisory describing a group of vulnerabilities known as Processor MMIO Stale Data Vulnerabilities. In addition to the security guidance for these four vulnerabilities, Microsoft has released this advisory to detail the recommended actions Microsoft customers should take to ensure complete remediation of these vulnerabilities.

The post ” VERT Threat Alert: June 2022 Patch Tuesday Analysis” appeared first on TripWire

Source:TripWire – Tyler Reguly

Tags: Cloud, Microsoft, Patch Tuesday, TripWire

Continue Reading

Previous New Zimbra Email Vulnerability Could Let Attackers Steal Your Login Credentials
Next Patch Tuesday: Microsoft Issues Fix for Actively Exploited ‘Follina’ Vulnerability

More Stories

  • Cyber Attacks
  • Data Breach

Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials

10 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Data Breach
  • Vulnerabilities

OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards

15 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys

1 day ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks

1 day ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign

1 day ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

2 days ago [email protected] (The Hacker News)

Recent Posts

  • Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials
  • OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards
  • FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys
  • New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
  • Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign

Tags

Android APT Bug CERT Cloud Compliance Coronavirus COVID-19 Critical Severity Encryption Exploit Facebook Finance Google Google Chrome Goverment Hacker Hacker News High Severity Instagram iPhone Java Linux Low Severity Malware Medium Severity Microsoft Moderate Severity Mozzila Firefox Oracle Patch Tuesday Phishing Privacy QuickHeal Ransomware RAT Sim The Hacker News Threatpost TikTok TripWire VMWARE Vulnerability Whatsapp Zoom
Copyright © 2020 All rights reserved | NGTEdu.com
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More here.Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT