Total CVEs

71

Critical

3

Important

68

Exploited

0

Publicly Disclosed

3

All CVEs this month 71

CVE Title Severity CVSS Product Exploited Disclosed Diffed
CVE-2022-21977 Media Foundation Information Disclosure Vulnerability Important 3.3 Microsoft Windows Codecs Library - - -
CVE-2022-21967 Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability Important 7 XBox - - -
CVE-2022-22010 Media Foundation Information Disclosure Vulnerability Important 4.4 Microsoft Windows Codecs Library - - -
CVE-2022-21975 Windows Hyper-V Denial of Service Vulnerability Important 4.7 Role: Windows Hyper-V - - -
CVE-2022-21990 Remote Desktop Client Remote Code Execution Vulnerability Important 8.8 Windows Remote Desktop - Yes -
CVE-2022-23265 Microsoft Defender for IoT Remote Code Execution Vulnerability Important 7.2 Microsoft Defender for IoT - - -
CVE-2022-23266 Microsoft Defender for IoT Elevation of Privilege Vulnerability Important 7.8 Microsoft Defender for IoT - - -
CVE-2022-23290 Windows Inking COM Elevation of Privilege Vulnerability Important 7.8 Windows COM - - -
CVE-2022-23291 Windows DWM Core Library Elevation of Privilege Vulnerability Important 7.8 Windows DWM Core Library - - -
CVE-2022-23293 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability Important 7.8 Windows Fast FAT Driver - - -
CVE-2022-23294 Windows Event Tracing Remote Code Execution Vulnerability Important 8.8 Windows Event Tracing - - -
CVE-2022-23295 Raw Image Extension Remote Code Execution Vulnerability Important 7.8 Microsoft Windows Codecs Library - - -
CVE-2022-23296 Windows Installer Elevation of Privilege Vulnerability Important 7.8 Windows Installer - - -
CVE-2022-23298 Windows NT OS Kernel Elevation of Privilege Vulnerability Important 7 Windows Kernel - - -
CVE-2022-23299 Windows PDEV Elevation of Privilege Vulnerability Important 7.8 Windows PDEV - - -
CVE-2022-23300 Raw Image Extension Remote Code Execution Vulnerability Important 7.8 Microsoft Windows Codecs Library - - -
CVE-2022-23301 HEVC Video Extensions Remote Code Execution Vulnerability Important 7.8 Microsoft Windows Codecs Library - - -
CVE-2022-22006 HEVC Video Extensions Remote Code Execution Vulnerability Critical 7.8 Microsoft Windows Codecs Library - - -
CVE-2022-22007 HEVC Video Extensions Remote Code Execution Vulnerability Important 7.8 Microsoft Windows Codecs Library - - -
CVE-2022-24451 VP9 Video Extensions Remote Code Execution Vulnerability Important 7.8 Microsoft Windows Codecs Library - - -
CVE-2022-24452 HEVC Video Extensions Remote Code Execution Vulnerability Important 7.8 Microsoft Windows Codecs Library - - -
CVE-2022-24453 HEVC Video Extensions Remote Code Execution Vulnerability Important 7.8 Microsoft Windows Codecs Library - - -
CVE-2022-24501 VP9 Video Extensions Remote Code Execution Vulnerability Critical 7.8 Microsoft Windows Codecs Library - - -
CVE-2022-24502 Windows HTML Platforms Security Feature Bypass Vulnerability Important 4.3 Windows HTML Platform - - -
CVE-2022-24454 Windows Security Support Provider Interface Elevation of Privilege Vulnerability Important 7.8 Windows Security Support Provider Interface - - -
CVE-2022-24503 Remote Desktop Protocol Client Information Disclosure Vulnerability Important 5.4 Windows Remote Desktop - - -
CVE-2022-24455 Windows CD-ROM Driver Elevation of Privilege Vulnerability Important 7.8 Windows CD-ROM Driver - - -
CVE-2022-24456 HEVC Video Extensions Remote Code Execution Vulnerability Important 7.8 Microsoft Windows Codecs Library - - -
CVE-2022-24457 HEIF Image Extensions Remote Code Execution Vulnerability Important 7.8 Microsoft Windows Codecs Library - - -
CVE-2022-24506 Azure Site Recovery Elevation of Privilege Vulnerability Important 6.5 Azure Site Recovery - - -
CVE-2022-24507 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Important 7.8 Windows Ancillary Function Driver for WinSock - - -
CVE-2022-24459 Windows Fax and Scan Service Elevation of Privilege Vulnerability Important 7.8 Windows Fax and Scan Service - Yes -
CVE-2022-24463 Microsoft Exchange Server Spoofing Vulnerability Important 6.5 Microsoft Exchange Server - - -
CVE-2022-24512 .NET and Visual Studio Remote Code Execution Vulnerability Important 6.3 .NET and Visual Studio - Yes -
CVE-2022-24464 .NET and Visual Studio Denial of Service Vulnerability Important 7.5 .NET and Visual Studio - - -
CVE-2022-24465 Microsoft Intune Portal for iOS Security Feature Bypass Vulnerability Important 3.3 Microsoft Intune - - -
CVE-2022-24515 Azure Site Recovery Elevation of Privilege Vulnerability Important 6.5 Azure Site Recovery - - -
CVE-2022-24467 Azure Site Recovery Remote Code Execution Vulnerability Important 7.2 Azure Site Recovery - - -
CVE-2022-24522 Skype Extension for Chrome Information Disclosure Vulnerability Important 6.5 Skype Extension for Chrome - - -
CVE-2022-26899 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Important 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2022-21973 Windows Media Center Update Denial of Service Vulnerability Important 5.5 Windows Media - - -
CVE-2022-23253 Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability Important 6.5 Windows Point-to-Point Tunneling Protocol - - -
CVE-2022-23277 Microsoft Exchange Server Remote Code Execution Vulnerability Critical 8.8 Microsoft Exchange Server - - -
CVE-2022-23278 Microsoft Defender for Endpoint Spoofing Vulnerability Important 5.9 Microsoft Defender for Endpoint - - -
CVE-2022-23281 Windows Common Log File System Driver Information Disclosure Vulnerability Important 5.5 Windows Common Log File System Driver - - -
CVE-2022-23282 Paint 3D Remote Code Execution Vulnerability Important 7.8 Paint 3D - - -
CVE-2022-23283 Windows ALPC Elevation of Privilege Vulnerability Important 7 Windows ALPC - - -
CVE-2022-23284 Windows Print Spooler Elevation of Privilege Vulnerability Important 7.2 Windows Print Spooler Components - - -
CVE-2022-23285 Remote Desktop Client Remote Code Execution Vulnerability Important 8.8 Windows Remote Desktop - - -
CVE-2022-23286 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Important 7 Windows Cloud Files Mini Filter Driver - - -
CVE-2022-23287 Windows ALPC Elevation of Privilege Vulnerability Important 7 Windows ALPC - - -
CVE-2022-23288 Windows DWM Core Library Elevation of Privilege Vulnerability Important 7 Windows DWM Core Library - - -
CVE-2022-23297 Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability Important 5.5 Windows Kernel - - -
CVE-2022-24505 Windows ALPC Elevation of Privilege Vulnerability Important 7 Windows ALPC - - -
CVE-2022-24508 Win32 File Enumeration Remote Code Execution Vulnerability Important 8.8 Windows SMB Server - - -
CVE-2022-24460 Tablet Windows User Interface Application Elevation of Privilege Vulnerability Important 7 Tablet Windows User Interface - - -
CVE-2022-24509 Microsoft Office Visio Remote Code Execution Vulnerability Important 7.8 Microsoft Office Visio - - -
CVE-2022-24461 Microsoft Office Visio Remote Code Execution Vulnerability Important 7.8 Microsoft Office Visio - - -
CVE-2022-24510 Microsoft Office Visio Remote Code Execution Vulnerability Important 7.8 Microsoft Office Visio - - -
CVE-2022-24462 Microsoft Word Security Feature Bypass Vulnerability Important 5.5 Microsoft Office Word - - -
CVE-2022-24511 Microsoft Office Word Tampering Vulnerability Important 5.5 Microsoft Office Word - - -
CVE-2022-24468 Azure Site Recovery Remote Code Execution Vulnerability Important 7.2 Azure Site Recovery - - -
CVE-2022-24469 Azure Site Recovery Elevation of Privilege Vulnerability Important 8.1 Azure Site Recovery - - -
CVE-2022-24517 Azure Site Recovery Remote Code Execution Vulnerability Important 7.2 Azure Site Recovery - - -
CVE-2022-24470 Azure Site Recovery Remote Code Execution Vulnerability Important 7.2 Azure Site Recovery - - -
CVE-2022-24518 Azure Site Recovery Elevation of Privilege Vulnerability Important 6.5 Azure Site Recovery - - -
CVE-2022-24519 Azure Site Recovery Elevation of Privilege Vulnerability Important 6.5 Azure Site Recovery - - -
CVE-2022-24471 Azure Site Recovery Remote Code Execution Vulnerability Important 7.2 Azure Site Recovery - - -
CVE-2022-24520 Azure Site Recovery Remote Code Execution Vulnerability Important 7.2 Azure Site Recovery - - -
CVE-2022-24525 Windows Update Stack Elevation of Privilege Vulnerability Important 7 Windows Update Stack - - -
CVE-2022-24526 Visual Studio Code Spoofing Vulnerability Important 6.1 Visual Studio Code - - -

Threat Categories 7

Threat Category CVEs Critical
Remote Code Execution 28 3
Elevation of Privilege 26 -
Information Disclosure 6 -
Denial of Service 4 -
Security Feature Bypass 3 -
Spoofing 3 -
Tampering 1 -

Affected Products 37

Product CVEs Exploited
Microsoft Windows Codecs Library 13 -
Azure Site Recovery 11 -
Microsoft Office Visio 3 -
Windows ALPC 3 -
Windows Remote Desktop 3 -
.NET and Visual Studio 2 -
Microsoft Defender for IoT 2 -
Microsoft Exchange Server 2 -
Microsoft Office Word 2 -
Windows DWM Core Library 2 -
Windows Kernel 2 -
Microsoft Defender for Endpoint 1 -
Microsoft Edge (Chromium-based) 1 -
Microsoft Intune 1 -
Paint 3D 1 -
Role: Windows Hyper-V 1 -
Skype Extension for Chrome 1 -
Tablet Windows User Interface 1 -
Visual Studio Code 1 -
Windows Ancillary Function Driver for WinSock 1 -
Windows CD-ROM Driver 1 -
Windows COM 1 -
Windows Cloud Files Mini Filter Driver 1 -
Windows Common Log File System Driver 1 -
Windows Event Tracing 1 -
Windows Fast FAT Driver 1 -
Windows Fax and Scan Service 1 -
Windows HTML Platform 1 -
Windows Installer 1 -
Windows Media 1 -
Windows PDEV 1 -
Windows Point-to-Point Tunneling Protocol 1 -
Windows Print Spooler Components 1 -
Windows SMB Server 1 -
Windows Security Support Provider Interface 1 -
Windows Update Stack 1 -
XBox 1 -