Microsoft CVE-2022-44693: Microsoft SharePoint Server Remote Code Execution Vulnerability

Home/Compromised, Exploitation, Internet Security, IOC's, malicious cyber actors, Microsoft, Security Advisory, Security Update/Microsoft CVE-2022-44693: Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft CVE-2022-44693: Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft on Tuesday released patches for 48 vulnerabilities in seven Microsoft product families. This includes 6 Critical-class issues affecting Microsoft Dynamics, SharePoint, and Windows.

Of the 53 patches released in the December Patch Tuesday run, six are rated critical, 43 are rated important, and three are rated moderately severe. Microsoft also fixed two zero-day vulnerabilities, one of which was under active exploitation.

CVE-2022-44693

RCE vulnerabilities in Microsoft SharePoint Server that both received a CVSSv3 score of 8.8. An authenticated attacker with permission to use Manage Lists in SharePoint could exploit these vulnerabilities to execute code remotely

“To exploit it, attackers only need access to the basic user account with Manage List permissions, which most companies grant to all SharePoint users by default,” warned Walters.

Talos researchers also pointed out six important vulnerabilities that Microsoft considers to be “more likely” to undergo exploitation:

  1. CVE-2022-41121: Windows Graphics Component Elevation of Privilege Vulnerability
  2. CVE-2022-44671: Windows Graphics Component Elevation of Privilege Vulnerability
  3. CVE-2022-44673: Windows Client Server Run-Time Subsystem (CSRSS) Elevation of Privilege Vulnerability
  4. CVE-2022-44675: Windows Bluetooth Driver Elevation of Privilege Vulnerability
  5. CVE-2022-44683: Windows Kernel Elevation of Privilege

Mitigation

Install updates from vendor’s website.Vulnerable software versions

Microsoft SharePoint Server Subscription Edition: All versions

Microsoft SharePoint Foundation: 2013 Service Pack 1

Microsoft SharePoint Enterprise Server: 2013 Service Pack 1 – 2016

Follow Us on: Twitter, InstagramFacebook to get the latest security news!

About the Author:

FirstHackersNews- Identifies Security

Leave A Comment

Subscribe to our newsletter to receive security tips everday!