JPCERT-AT-2022-0031 JPCERT/CC 2022-11-09 <<< JPCERT/CC Alert 2022-11-09 >>> Microsoft Releases November 2022 Security Updates https://www.jpcert.or.jp/english/at/2022/at220031.html I. Overview Microsoft has released November 2022 Security Updates to address the vulnerabilities in their products. Remote attackers leveraging these vulnerabilities may be able to execute arbitrary code. It is recommended to check the information provided by Microsoft and apply the updates. Microsoft Corporation November 2022 Security Updates https://msrc.microsoft.com/update-guide/en-us/releaseNote/2022-Nov Microsoft Corporation Microsoft Security Updates for November 2022 (Monthly) (Japanese) https://msrc-blog.microsoft.com/2022/11/08/202211-security-update/ According to Microsoft, among these vulnerabilities, the following four vulnerability have been confirmed to be exploited in the wild. Please consider applying the security update programs by referring to the information provided by Microsoft. CVE-2022-41073 Windows Print Spooler Elevation of Privilege Vulnerability https://msrc.microsoft.com/update-guide/en-us/vulnerability/CVE-2022-41073 CVE-2022-41091 Windows Mark of the Web Security Feature Bypass Vulnerability https://msrc.microsoft.com/update-guide/en-us/vulnerability/CVE-2022-41091 CVE-2022-41125 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability https://msrc.microsoft.com/update-guide/en-us/vulnerability/CVE-2022-41125 CVE-2022-41128 Windows Scripting Languages Remote Code Execution Vulnerability https://msrc.microsoft.com/update-guide/en-us/vulnerability/CVE-2022-41128 II. Solution Please apply the security update programs through Microsoft Update, Windows Update, etc. as soon as possible. Microsoft Update Catalog https://www.catalog.update.microsoft.com/ Windows Update: FAQ https://support.microsoft.com/en-us/help/12373/windows-update-faq III. Related information The security update was released for the zero-day vulnerabilities (CVE-2022-41040, CVE-2022-41082) in Microsoft Exchange Server that Microsoft disclosed on September 30, 2022 (local time). It is recommended to apply update immediately. Microsoft Corporation Customer Guidance for Reported Zero-day Vulnerabilities in Microsoft Exchange Server https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/ Microsoft The Exchange Team Released: November 2022 Exchange Server Security Updates https://techcommunity.microsoft.com/t5/exchange-team-blog/released-november-2022-exchange-server-security-updates/ba-p/3669045 IV. References Microsoft Corporation Release Notes https://msrc.microsoft.com/update-guide/releaseNote If you have any information regarding this alert, please contact JPCERT/CC. ====================================================================== JPCERT Coordination Center (Early Warning Group) MAIL: ew-info@jpcert.or.jp https://www.jpcert.or.jp/english/