Patch Tuesday Archive
Patch Tuesday January 2022
Total CVEs
102
Critical
8
Important
92
Exploited
2
Publicly Disclosed
5
All CVEs this month 102
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2022-21852 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM Core Library | - | - | - |
| CVE-2022-21919 | Windows User Profile Service Elevation of Privilege Vulnerability | Important | 7 |
Windows User Profile Service | - | Yes | - |
| CVE-2022-21918 | DirectX Graphics Kernel File Denial of Service Vulnerability | Important | 6.5 |
Windows DirectX | - | - | - |
| CVE-2022-21917 | HEVC Video Extensions Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2022-21915 | Windows GDI+ Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-21932 | Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability | Important | 5.4 |
Microsoft Dynamics | - | - | - |
| CVE-2022-21833 | Virtual Machine IDE Drive Elevation of Privilege Vulnerability | Critical | 7.8 |
Windows Virtual Machine IDE Drive | - | - | - |
| CVE-2022-21834 | Windows User-mode Driver Framework Reflector Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows User-mode Driver Framework | - | - | - |
| CVE-2022-21835 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Cryptographic Services | - | - | - |
| CVE-2022-21836 | Windows Certificate Spoofing Vulnerability | Important | 7.8 |
Windows Certificates | - | Yes | - |
| CVE-2022-21838 | Windows Cleanup Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Cleanup Manager | - | - | - |
| CVE-2022-21839 | Windows Event Tracing Discretionary Access Control List Denial of Service Vulnerability | Important | 5.5 |
Windows Event Tracing | - | Yes | - |
| CVE-2022-21840 | Microsoft Office Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Office | - | - | - |
| CVE-2022-21841 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2022-21857 | Active Directory Domain Services Elevation of Privilege Vulnerability | Critical | 8.8 |
Windows Active Directory | - | - | - |
| CVE-2022-21858 | Windows Bind Filter Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Bind Filter Driver | - | - | - |
| CVE-2022-21859 | Windows Accounts Control Elevation of Privilege Vulnerability | Important | 7 |
Windows Account Control | - | - | - |
| CVE-2022-21860 | Windows AppContracts API Server Elevation of Privilege Vulnerability | Important | 7 |
Windows AppContracts API Server | - | - | - |
| CVE-2022-21861 | Task Flow Data Engine Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Task Flow Data Engine | - | - | - |
| CVE-2022-21862 | Windows Application Model Core API Elevation of Privilege Vulnerability | Important | 7 |
Windows Application Model | - | - | - |
| CVE-2022-21863 | Windows StateRepository API Server file Elevation of Privilege Vulnerability | Important | 7 |
Windows StateRepository API | - | - | - |
| CVE-2022-21864 | Windows UI Immersive Server API Elevation of Privilege Vulnerability | Important | 7 |
Windows UI Immersive Server | - | - | - |
| CVE-2022-21865 | Connected Devices Platform Service Elevation of Privilege Vulnerability | Important | 7 |
Windows Connected Devices Platform Service | - | - | - |
| CVE-2022-21866 | Windows System Launcher Elevation of Privilege Vulnerability | Important | 7 |
Windows System Launcher | - | - | - |
| CVE-2022-21867 | Windows Push Notifications Apps Elevation of Privilege Vulnerability | Important | 7 |
Windows Push Notifications | - | - | - |
| CVE-2022-21868 | Windows Devices Human Interface Elevation of Privilege Vulnerability | Important | 7 |
Windows Devices Human Interface | - | - | - |
| CVE-2022-21869 | Clipboard User Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Clipboard User Service | - | - | - |
| CVE-2022-21870 | Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability | Important | 7.8 |
Tablet Windows User Interface | - | - | - |
| CVE-2022-21871 | Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Diagnostic Hub | - | - | - |
| CVE-2022-21872 | Windows Event Tracing Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Event Tracing | - | - | - |
| CVE-2022-21873 | Tile Data Repository Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Tile Data Repository | - | - | - |
| CVE-2022-21874 | Windows Security Center API Remote Code Execution Vulnerability | Important | 9.8 |
Windows Security Center | - | Yes | - |
| CVE-2022-21875 | Windows Storage Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Storage | - | - | - |
| CVE-2022-21876 | Win32k Information Disclosure Vulnerability | Important | 5.5 |
Windows Win32K | - | - | - |
| CVE-2022-21877 | Storage Spaces Controller Information Disclosure Vulnerability | Important | 5.5 |
Windows Storage Spaces Controller | - | - | Yes |
| CVE-2022-21878 | Windows Geolocation Service Remote Code Execution Vulnerability | Important | 7.8 |
Windows Geolocation Service | - | - | - |
| CVE-2022-21879 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2022-21880 | Windows GDI+ Information Disclosure Vulnerability | Important | 7.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-21881 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7 |
Windows Kernel | - | - | - |
| CVE-2022-21882 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K | Yes | - | - |
| CVE-2022-21843 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | Important | 7.5 |
Windows IKE Extension | - | - | - |
| CVE-2022-21883 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | Important | 7.5 |
Windows IKE Extension | - | - | - |
| CVE-2022-21884 | Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Local Security Authority Subsystem Service (LSASS) | - | - | - |
| CVE-2022-21885 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Remote Access Connection Manager | - | - | - |
| CVE-2022-21887 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K | - | - | - |
| CVE-2022-21888 | Windows Modern Execution Server Remote Code Execution Vulnerability | Important | 7.8 |
Windows Modern Execution Server | - | - | - |
| CVE-2022-21892 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | Important | 6.8 |
Windows Resilient File System (ReFS) | - | - | - |
| CVE-2022-21893 | Remote Desktop Protocol Remote Code Execution Vulnerability | Important | 8 |
Windows RDP | - | - | - |
| CVE-2022-21894 | Secure Boot Security Feature Bypass Vulnerability | Important | 4.4 |
Windows Secure Boot | - | - | - |
| CVE-2022-21900 | Windows Hyper-V Security Feature Bypass Vulnerability | Important | 4.6 |
Role: Windows Hyper-V | - | - | - |
| CVE-2022-21901 | Windows Hyper-V Elevation of Privilege Vulnerability | Important | 8 |
Role: Windows Hyper-V | - | - | - |
| CVE-2022-21902 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM Core Library | - | - | - |
| CVE-2022-21903 | Windows GDI Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-21904 | Windows GDI Information Disclosure Vulnerability | Important | 7.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-21905 | Windows Hyper-V Security Feature Bypass Vulnerability | Important | 8 |
Role: Windows Hyper-V | - | - | - |
| CVE-2022-21906 | Windows Defender Application Control Security Feature Bypass Vulnerability | Important | 5.5 |
Windows Defender | - | - | - |
| CVE-2022-21907 | HTTP Protocol Stack Remote Code Execution Vulnerability | Critical | 9.8 |
Windows HTTP Protocol Stack | - | - | - |
| CVE-2022-21908 | Windows Installer Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Installer | - | - | - |
| CVE-2022-21910 | Microsoft Cluster Port Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Cluster Port Driver | - | - | - |
| CVE-2022-21911 | .NET Framework Denial of Service Vulnerability | Important | 7.5 |
.NET Framework | - | - | - |
| CVE-2022-21912 | DirectX Graphics Kernel Remote Code Execution Vulnerability | Critical | 7.8 |
Windows DirectX | - | - | - |
| CVE-2022-21913 | Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass | Important | 7.5 |
Windows Local Security Authority | - | - | - |
| CVE-2022-21924 | Workstation Service Remote Protocol Security Feature Bypass Vulnerability | Important | 5.3 |
Windows Workstation Service Remote Protocol | - | - | - |
| CVE-2022-21925 | Windows BackupKey Remote Protocol Security Feature Bypass Vulnerability | Important | 5.3 |
Windows BackupKey Remote Protocol | - | - | - |
| CVE-2022-21958 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | Important | 6.8 |
Windows Resilient File System (ReFS) | - | - | - |
| CVE-2022-21959 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | Important | 6.8 |
Windows Resilient File System (ReFS) | - | - | - |
| CVE-2022-21960 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | Important | 6.8 |
Windows Resilient File System (ReFS) | - | - | - |
| CVE-2022-21961 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | Important | 6.8 |
Windows Resilient File System (ReFS) | - | - | - |
| CVE-2022-21962 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | Important | 6.8 |
Windows Resilient File System (ReFS) | - | - | - |
| CVE-2022-21963 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | Important | 6.8 |
Windows Resilient File System (ReFS) | - | - | - |
| CVE-2022-21964 | Remote Desktop Licensing Diagnoser Information Disclosure Vulnerability | Important | 5.5 |
Windows Remote Desktop | - | - | - |
| CVE-2022-21846 | Microsoft Exchange Server Remote Code Execution Vulnerability | Critical | 9 |
Microsoft Exchange Server | - | - | - |
| CVE-2022-21847 | Windows Hyper-V Denial of Service Vulnerability | Important | 6.5 |
Role: Windows Hyper-V | - | - | - |
| CVE-2022-21922 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2022-21921 | Windows Defender Credential Guard Security Feature Bypass Vulnerability | Important | 4.4 |
Windows Defender | - | - | - |
| CVE-2022-21920 | Windows Kerberos Elevation of Privilege Vulnerability | Important | 8.8 |
Windows Kerberos | - | - | - |
| CVE-2022-21848 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | Important | 7.5 |
Windows IKE Extension | - | - | - |
| CVE-2022-21849 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | Important | 9.8 |
Windows IKE Extension | - | - | Yes |
| CVE-2022-21850 | Remote Desktop Client Remote Code Execution Vulnerability | Important | 8.8 |
Windows RDP | - | - | - |
| CVE-2022-21851 | Remote Desktop Client Remote Code Execution Vulnerability | Important | 8.8 |
Windows RDP | - | - | - |
| CVE-2022-21855 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 9 |
Microsoft Exchange Server | - | - | - |
| CVE-2022-21916 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2022-21895 | Windows User Profile Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows User Profile Service | - | - | - |
| CVE-2022-21914 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Remote Access Connection Manager | - | - | - |
| CVE-2022-21837 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2022-21842 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2022-21889 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | Important | 7.5 |
Windows IKE Extension | - | - | - |
| CVE-2022-21890 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | Important | 7.5 |
Windows IKE Extension | - | - | - |
| CVE-2022-21891 | Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability | Important | 4.3 |
Microsoft Dynamics | - | - | - |
| CVE-2022-21896 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important | 7 |
Windows DWM Core Library | - | - | - |
| CVE-2022-21897 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2022-21898 | DirectX Graphics Kernel Remote Code Execution Vulnerability | Critical | 9.8 |
Windows DirectX | - | - | - |
| CVE-2022-21899 | Windows Extensible Firmware Interface Security Feature Bypass Vulnerability | Important | 5.5 |
Windows UEFI | - | - | - |
| CVE-2022-21928 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | Important | 6.4 |
Windows Resilient File System (ReFS) | - | - | - |
| CVE-2022-21929 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Moderate | 2.5 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-21930 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Important | 4.2 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-21931 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Important | 4.2 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-21954 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 6.1 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-21969 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 9 |
Microsoft Exchange Server | - | - | - |
| CVE-2022-21970 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 6.1 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2013-3900 | WinVerifyTrust Signature Validation Vulnerability | Important | 7.4 |
WinVerifyTrust Signature Verification | Yes | Yes | - |
| CVE-2022-23258 | Microsoft Edge for Android Spoofing Vulnerability | Moderate | 4.3 |
Microsoft Edge (Chromium-based) | - | - | - |
Threat Categories 6
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 43 | 2 |
| Remote Code Execution | 30 | 6 |
| Security Feature Bypass | 10 | - |
| Denial of Service | 9 | - |
| Information Disclosure | 6 | - |
| Spoofing | 4 | - |
Affected Products 62
| Product | CVEs | Exploited |
|---|---|---|
| Windows Resilient File System (ReFS) | 8 | - |
| Microsoft Edge (Chromium-based) | 6 | - |
| Windows IKE Extension | 6 | - |
| Microsoft Graphics Component | 4 | - |
| Role: Windows Hyper-V | 4 | - |
| Microsoft Exchange Server | 3 | - |
| Windows DWM Core Library | 3 | - |
| Windows DirectX | 3 | - |
| Windows RDP | 3 | - |
| Windows Win32K | 3 | 1 |
| Microsoft Dynamics | 2 | - |
| Windows Common Log File System Driver | 2 | - |
| Windows Defender | 2 | - |
| Windows Event Tracing | 2 | - |
| Windows Kernel | 2 | - |
| Windows Remote Access Connection Manager | 2 | - |
| Windows User Profile Service | 2 | - |
| .NET Framework | 1 | - |
| Microsoft Office | 1 | - |
| Microsoft Office Excel | 1 | - |
| Microsoft Office SharePoint | 1 | - |
| Microsoft Office Word | 1 | - |
| Microsoft Windows Codecs Library | 1 | - |
| Tablet Windows User Interface | 1 | - |
| WinVerifyTrust Signature Verification | 1 | 1 |
| Windows Account Control | 1 | - |
| Windows Active Directory | 1 | - |
| Windows AppContracts API Server | 1 | - |
| Windows Application Model | 1 | - |
| Windows BackupKey Remote Protocol | 1 | - |
| Windows Bind Filter Driver | 1 | - |
| Windows Certificates | 1 | - |
| Windows Cleanup Manager | 1 | - |
| Windows Clipboard User Service | 1 | - |
| Windows Cluster Port Driver | 1 | - |
| Windows Connected Devices Platform Service | 1 | - |
| Windows Cryptographic Services | 1 | - |
| Windows Devices Human Interface | 1 | - |
| Windows Diagnostic Hub | 1 | - |
| Windows Geolocation Service | 1 | - |
| Windows HTTP Protocol Stack | 1 | - |
| Windows Installer | 1 | - |
| Windows Kerberos | 1 | - |
| Windows Local Security Authority | 1 | - |
| Windows Local Security Authority Subsystem Service (LSASS) | 1 | - |
| Windows Modern Execution Server | 1 | - |
| Windows Push Notifications | 1 | - |
| Windows Remote Desktop | 1 | - |
| Windows Remote Procedure Call Runtime | 1 | - |
| Windows Secure Boot | 1 | - |
| Windows Security Center | 1 | - |
| Windows StateRepository API | 1 | - |
| Windows Storage | 1 | - |
| Windows Storage Spaces Controller | 1 | - |
| Windows System Launcher | 1 | - |
| Windows Task Flow Data Engine | 1 | - |
| Windows Tile Data Repository | 1 | - |
| Windows UEFI | 1 | - |
| Windows UI Immersive Server | 1 | - |
| Windows User-mode Driver Framework | 1 | - |
| Windows Virtual Machine IDE Drive | 1 | - |
| Windows Workstation Service Remote Protocol | 1 | - |