Patch Tuesday Archive
Patch Tuesday February 2022
Total CVEs
52
Critical
0
Important
50
Exploited
0
Publicly Disclosed
1
All CVEs this month 52
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2022-21971 | Windows Runtime Remote Code Execution Vulnerability | Important | 7.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2022-21981 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2022-21974 | Roaming Security Rights Management Services Remote Code Execution Vulnerability | Important | 7.8 |
Roaming Security Rights Management Services | - | - | - |
| CVE-2022-21844 | HEVC Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2022-21926 | HEVC Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2022-21927 | HEVC Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2022-21957 | Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability | Important | 7.2 |
Microsoft Dynamics | - | - | - |
| CVE-2022-21965 | Microsoft Teams Denial of Service Vulnerability | Important | 7.5 |
Microsoft Teams | - | - | - |
| CVE-2022-22709 | VP9 Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2022-22710 | Windows Common Log File System Driver Denial of Service Vulnerability | Important | 5.5 |
Windows Common Log File System Driver | - | - | - |
| CVE-2022-22712 | Windows Hyper-V Denial of Service Vulnerability | Important | 5.6 |
Role: Windows Hyper-V | - | - | - |
| CVE-2022-21987 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2022-21988 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2022-23254 | Microsoft Power BI Information Disclosure Vulnerability | Important | 4.9 |
Power BI | - | - | - |
| CVE-2022-23269 | Microsoft Dynamics GP Spoofing Vulnerability | Important | 5.4 |
Microsoft Dynamics GP | - | - | - |
| CVE-2022-23271 | Microsoft Dynamics GP Elevation Of Privilege Vulnerability | Important | 6.5 |
Microsoft Dynamics GP | - | - | - |
| CVE-2022-23272 | Microsoft Dynamics GP Elevation Of Privilege Vulnerability | Important | 8.1 |
Microsoft Dynamics GP | - | - | - |
| CVE-2022-23273 | Microsoft Dynamics GP Elevation Of Privilege Vulnerability | Important | 7.1 |
Microsoft Dynamics GP | - | - | - |
| CVE-2022-23274 | Microsoft Dynamics GP Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Dynamics GP | - | - | - |
| CVE-2022-23276 | SQL Server for Linux Containers Elevation of Privilege Vulnerability | Important | 7.8 |
SQL Server | - | - | - |
| CVE-2022-21968 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | Important | 4.3 |
Microsoft Office SharePoint | - | - | - |
| CVE-2022-22715 | Named Pipe File System Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Named Pipe File System | - | - | - |
| CVE-2022-22716 | Microsoft Excel Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Office Excel | - | - | - |
| CVE-2022-22717 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7 |
Windows Print Spooler Components | - | - | - |
| CVE-2022-22718 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Print Spooler Components | - | - | - |
| CVE-2022-21984 | Windows DNS Server Remote Code Execution Vulnerability | Important | 8.8 |
Role: DNS Server | - | - | - |
| CVE-2022-21985 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | Important | 5.5 |
Windows Remote Access Connection Manager | - | - | - |
| CVE-2022-21986 | .NET Denial of Service Vulnerability | Important | 7.5 |
Kestrel Web Server | - | - | - |
| CVE-2022-21989 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | Yes | - |
| CVE-2022-21991 | Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability | Important | 8.1 |
Visual Studio Code | - | - | - |
| CVE-2022-21992 | Windows Mobile Device Management Remote Code Execution Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2022-21993 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | Important | 7.5 |
Windows Kernel-Mode Drivers | - | - | - |
| CVE-2022-21994 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM Core Library | - | - | - |
| CVE-2022-21995 | Windows Hyper-V Remote Code Execution Vulnerability | Important | 7.9 |
Role: Windows Hyper-V | - | - | - |
| CVE-2022-21996 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K | - | - | - |
| CVE-2022-21997 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.1 |
Windows Print Spooler Components | - | - | - |
| CVE-2022-21998 | Windows Common Log File System Driver Information Disclosure Vulnerability | Important | 5.5 |
Windows Common Log File System Driver | - | - | - |
| CVE-2022-21999 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Print Spooler Components | - | - | - |
| CVE-2022-22000 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2022-22001 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Remote Access Connection Manager | - | - | - |
| CVE-2022-22002 | Windows User Account Profile Picture Denial of Service Vulnerability | Important | 5.5 |
Windows User Account Profile | - | - | - |
| CVE-2022-22003 | Microsoft Office Graphics Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2022-22004 | Microsoft Office ClickToRun Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2022-22005 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2022-23252 | Microsoft Office Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Office | - | - | - |
| CVE-2022-23255 | Microsoft OneDrive for Android Security Feature Bypass Vulnerability | Important | 5.9 |
Microsoft OneDrive | - | - | - |
| CVE-2022-23256 | Azure Data Explorer Spoofing Vulnerability | Important | 4.3 |
Azure Data Explorer | - | - | - |
| CVE-2022-23261 | Microsoft Edge (Chromium-based) Tampering Vulnerability | Moderate | 5.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-23262 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 6.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-23263 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 7.7 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-23264 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Low | 4.7 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-23280 | Microsoft Outlook for Mac Security Feature Bypass Vulnerability | Important | 5.3 |
Microsoft Office Outlook | - | - | - |
Threat Categories 7
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 17 | - |
| Remote Code Execution | 16 | - |
| Information Disclosure | 6 | - |
| Denial of Service | 5 | - |
| Spoofing | 4 | - |
| Security Feature Bypass | 3 | - |
| Tampering | 1 | - |
Affected Products 29
| Product | CVEs | Exploited |
|---|---|---|
| Microsoft Dynamics GP | 5 | - |
| Microsoft Edge (Chromium-based) | 4 | - |
| Microsoft Windows Codecs Library | 4 | - |
| Windows Common Log File System Driver | 4 | - |
| Windows Print Spooler Components | 4 | - |
| Microsoft Office | 3 | - |
| Microsoft Office SharePoint | 3 | - |
| Role: Windows Hyper-V | 2 | - |
| Windows Kernel | 2 | - |
| Windows Remote Access Connection Manager | 2 | - |
| Azure Data Explorer | 1 | - |
| Kestrel Web Server | 1 | - |
| Microsoft Dynamics | 1 | - |
| Microsoft Office Excel | 1 | - |
| Microsoft Office Outlook | 1 | - |
| Microsoft Office Visio | 1 | - |
| Microsoft OneDrive | 1 | - |
| Microsoft Teams | 1 | - |
| Power BI | 1 | - |
| Roaming Security Rights Management Services | 1 | - |
| Role: DNS Server | 1 | - |
| SQL Server | 1 | - |
| Visual Studio Code | 1 | - |
| Windows DWM Core Library | 1 | - |
| Windows Kernel-Mode Drivers | 1 | - |
| Windows Named Pipe File System | 1 | - |
| Windows Remote Procedure Call Runtime | 1 | - |
| Windows User Account Profile | 1 | - |
| Windows Win32K | 1 | - |