Patch Tuesday Archive
Patch Tuesday June 2022
Total CVEs
56
Critical
3
Important
49
Exploited
0
Publicly Disclosed
0
All CVEs this month 56
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2022-29119 | HEVC Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2022-22018 | HEVC Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2022-22021 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Moderate | 8.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-29111 | HEVC Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2022-30131 | Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Container Isolation FS Filter Driver | - | - | - |
| CVE-2022-30132 | Windows Container Manager Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Container Manager Service | - | - | - |
| ADV220002 | Microsoft Guidance on Intel Processor MMIO Stale Data Vulnerabilities | Unknown | - | Intel | - | - | - |
| CVE-2022-30135 | Windows Media Center Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Media | - | - | - |
| CVE-2022-30136 | Windows Network File System Remote Code Execution Vulnerability | Critical | 9.8 |
Windows Network File System | - | - | - |
| CVE-2022-30137 | Azure Service Fabric Container Elevation of Privilege Vulnerability | Important | 6.7 |
Azure Service Fabric Container | - | - | - |
| CVE-2022-30140 | Windows iSCSI Discovery Service Remote Code Execution Vulnerability | Important | 7.5 |
Windows iSCSI | - | - | - |
| CVE-2022-30141 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 8.1 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2022-30142 | Windows File History Remote Code Execution Vulnerability | Important | 7.5 |
Windows File History Service | - | - | - |
| CVE-2022-30143 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 7.5 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2022-30145 | Windows Encrypting File System (EFS) Remote Code Execution Vulnerability | Important | 7.5 |
Windows Encrypting File System (EFS) | - | - | - |
| CVE-2022-30148 | Windows Desired State Configuration (DSC) Information Disclosure Vulnerability | Important | 5.5 |
Windows PowerShell | - | - | - |
| CVE-2022-30149 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 7.5 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2022-30150 | Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability | Important | 7.5 |
Windows Defender | - | - | - |
| CVE-2022-30151 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2022-30152 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | Important | 7.5 |
Windows Network Address Translation (NAT) | - | - | - |
| CVE-2022-30153 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 8.8 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2022-30154 | Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability | Important | 5.3 |
Remote Volume Shadow Copy Service (RVSS) | - | - | - |
| CVE-2022-30155 | Windows Kernel Denial of Service Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2022-30157 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2022-30158 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2022-30159 | Microsoft Office Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Office | - | - | - |
| CVE-2022-30160 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows ALPC | - | - | - |
| CVE-2022-30161 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 8.8 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2022-30162 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2022-30163 | Windows Hyper-V Remote Code Execution Vulnerability | Critical | 8.5 |
Role: Windows Hyper-V | - | - | - |
| CVE-2022-30164 | Kerberos AppContainer Security Feature Bypass Vulnerability | Important | 7.8 |
Windows Kerberos | - | - | - |
| CVE-2022-30167 | AV1 Video Extension Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2022-30165 | Windows Kerberos Elevation of Privilege Vulnerability | Important | 8.8 |
Windows Kerberos | - | - | - |
| CVE-2022-30171 | Microsoft Office Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Office | - | - | - |
| CVE-2022-30172 | Microsoft Office Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Office | - | - | - |
| CVE-2022-30173 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2022-30174 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2022-30177 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | Important | 7.8 |
Azure Real Time Operating System | - | - | - |
| CVE-2022-30178 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | Important | 7.8 |
Azure Real Time Operating System | - | - | - |
| CVE-2022-30179 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | Important | 7.8 |
Azure Real Time Operating System | - | - | - |
| CVE-2022-30180 | Azure RTOS GUIX Studio Information Disclosure Vulnerability | Important | 7.8 |
Azure Real Time Operating System | - | - | - |
| CVE-2022-30184 | .NET and Visual Studio Information Disclosure Vulnerability | Important | 5.5 |
.NET and Visual Studio | - | - | - |
| CVE-2022-30188 | HEVC Video Extensions Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2022-30189 | Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability | Important | 6.5 |
Windows Autopilot | - | - | - |
| CVE-2022-29143 | Microsoft SQL Server Remote Code Execution Vulnerability | Important | 7.5 |
SQL Server | - | - | - |
| CVE-2022-29149 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | Important | 7.8 |
Azure OMI | - | - | - |
| CVE-2022-30139 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Critical | 7.5 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2022-30146 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 7.5 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2022-30147 | Windows Installer Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Installer | - | - | - |
| CVE-2022-30166 | Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Local Security Authority Subsystem Service (LSASS) | - | - | - |
| CVE-2022-30168 | Microsoft Photos App Remote Code Execution Vulnerability | Important | 7.8 |
Windows App Store | - | - | - |
| CVE-2022-30193 | AV1 Video Extension Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2022-30192 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Moderate | 8.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-33638 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Moderate | 8.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-33639 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 8.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-33680 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 8.3 |
Microsoft Edge (Chromium-based) | - | - | - |
Threat Categories 7
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 28 | 3 |
| Elevation of Privilege | 16 | - |
| Information Disclosure | 7 | - |
| Denial of Service | 2 | - |
| Security Feature Bypass | 1 | - |
| Spoofing | 1 | - |
| Unknown | 1 | - |
Affected Products 32
| Product | CVEs | Exploited |
|---|---|---|
| Windows LDAP - Lightweight Directory Access Protocol | 7 | - |
| Microsoft Windows Codecs Library | 6 | - |
| Microsoft Edge (Chromium-based) | 5 | - |
| Azure Real Time Operating System | 4 | - |
| Microsoft Office | 4 | - |
| Microsoft Office SharePoint | 2 | - |
| Windows Kerberos | 2 | - |
| Windows Kernel | 2 | - |
| .NET and Visual Studio | 1 | - |
| Azure OMI | 1 | - |
| Azure Service Fabric Container | 1 | - |
| Intel | 1 | - |
| Microsoft Office Excel | 1 | - |
| Remote Volume Shadow Copy Service (RVSS) | 1 | - |
| Role: Windows Hyper-V | 1 | - |
| SQL Server | 1 | - |
| Windows ALPC | 1 | - |
| Windows Ancillary Function Driver for WinSock | 1 | - |
| Windows App Store | 1 | - |
| Windows Autopilot | 1 | - |
| Windows Container Isolation FS Filter Driver | 1 | - |
| Windows Container Manager Service | 1 | - |
| Windows Defender | 1 | - |
| Windows Encrypting File System (EFS) | 1 | - |
| Windows File History Service | 1 | - |
| Windows Installer | 1 | - |
| Windows Local Security Authority Subsystem Service (LSASS) | 1 | - |
| Windows Media | 1 | - |
| Windows Network Address Translation (NAT) | 1 | - |
| Windows Network File System | 1 | - |
| Windows PowerShell | 1 | - |
| Windows iSCSI | 1 | - |