Patch Tuesday Archive
Patch Tuesday July 2022
Total CVEs
82
Critical
4
Important
77
Exploited
1
Publicly Disclosed
0
All CVEs this month 82
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2022-21845 | Windows Kernel Information Disclosure Vulnerability | Important | 4.7 |
Windows Kernel | - | - | - |
| CVE-2022-22711 | Windows BitLocker Information Disclosure Vulnerability | Important | 5.7 |
Windows BitLocker | - | - | - |
| CVE-2022-33637 | Microsoft Defender for Endpoint Tampering Vulnerability | Important | 6.5 |
Microsoft Defender for Endpoint | - | - | - |
| CVE-2022-33641 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 6.5 |
Azure Site Recovery | - | - | - |
| CVE-2022-33642 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 4.9 |
Azure Site Recovery | - | - | - |
| CVE-2022-33643 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 6.5 |
Azure Site Recovery | - | - | - |
| CVE-2022-30181 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 6.5 |
Azure Site Recovery | - | - | - |
| CVE-2022-30187 | Azure Storage Library Information Disclosure Vulnerability | Important | 4.7 |
Azure Storage Library | - | - | - |
| CVE-2022-30202 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | Important | 7 |
Windows Advanced Local Procedure Call | - | - | - |
| CVE-2022-30203 | Windows Boot Manager Security Feature Bypass Vulnerability | Important | 7.4 |
Windows Boot Manager | - | - | - |
| CVE-2022-30205 | Windows Group Policy Elevation of Privilege Vulnerability | Important | 6.6 |
Windows Group Policy | - | - | - |
| CVE-2022-30206 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Print Spooler Components | - | - | - |
| CVE-2022-30208 | Windows Security Account Manager (SAM) Denial of Service Vulnerability | Important | 6.5 |
Windows Security Account Manager | - | - | - |
| CVE-2022-30209 | Windows IIS Server Elevation of Privilege Vulnerability | Important | 7.4 |
Windows IIS | - | - | - |
| CVE-2022-30211 | Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | Important | 7.5 |
Windows Point-to-Point Tunneling Protocol | - | - | - |
| CVE-2022-30212 | Windows Connected Devices Platform Service Information Disclosure Vulnerability | Important | 4.7 |
Windows Connected Devices Platform Service | - | - | - |
| CVE-2022-30213 | Windows GDI+ Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-30214 | Windows DNS Server Remote Code Execution Vulnerability | Important | 6.6 |
Role: DNS Server | - | - | - |
| CVE-2022-30215 | Active Directory Federation Services Elevation of Privilege Vulnerability | Important | 7.5 |
Windows Active Directory | - | - | - |
| CVE-2022-30216 | Windows Server Service Tampering Vulnerability | Important | 8.8 |
Windows Server Service | - | - | - |
| CVE-2022-30220 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Storage | - | - | - |
| CVE-2022-30221 | Windows Graphics Component Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-30222 | Windows Shell Remote Code Execution Vulnerability | Important | 8.4 |
Windows Shell | - | - | - |
| CVE-2022-30223 | Windows Hyper-V Information Disclosure Vulnerability | Important | 5.7 |
Role: Windows Hyper-V | - | - | - |
| CVE-2022-30224 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | Important | 7 |
Windows Advanced Local Procedure Call | - | - | - |
| CVE-2022-30225 | Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability | Important | 7.1 |
Windows Media | - | - | - |
| CVE-2022-30226 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.1 |
Windows Print Spooler Components | - | - | - |
| CVE-2022-22022 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.1 |
Windows Print Spooler Components | - | - | - |
| CVE-2022-22023 | Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability | Important | 6.6 |
Windows Portable Device Enumerator Service | - | - | - |
| CVE-2022-22024 | Windows Fax Service Remote Code Execution Vulnerability | Important | 7.8 |
Role: Windows Fax Service | - | - | - |
| CVE-2022-22025 | Windows Internet Information Services Cachuri Module Denial of Service Vulnerability | Important | 7.5 |
Windows IIS | - | - | - |
| CVE-2022-22026 | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | Important | 8.8 |
Windows Client/Server Runtime Subsystem | - | - | - |
| CVE-2022-22027 | Windows Fax Service Remote Code Execution Vulnerability | Important | 7.8 |
Role: Windows Fax Service | - | - | - |
| CVE-2022-22028 | Windows Network File System Information Disclosure Vulnerability | Important | 5.9 |
Windows Network File System | - | - | - |
| CVE-2022-22029 | Windows Network File System Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Network File System | - | - | - |
| CVE-2022-22031 | Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Credential Guard | - | - | - |
| CVE-2022-22034 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-22036 | Performance Counters for Windows Elevation of Privilege Vulnerability | Important | 7 |
Windows Performance Counters | - | - | - |
| CVE-2022-22037 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | Important | 7.5 |
Windows Advanced Local Procedure Call | - | - | - |
| CVE-2022-22038 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2022-22039 | Windows Network File System Remote Code Execution Vulnerability | Critical | 7.5 |
Windows Network File System | - | - | - |
| CVE-2022-22040 | Internet Information Services Dynamic Compression Module Denial of Service Vulnerability | Important | 7.3 |
Windows IIS | - | - | - |
| CVE-2022-22041 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 6.8 |
Windows Print Spooler Components | - | - | - |
| CVE-2022-22042 | Windows Hyper-V Information Disclosure Vulnerability | Important | 6.5 |
Role: Windows Hyper-V | - | - | - |
| CVE-2022-22043 | Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Fast FAT Driver | - | - | - |
| CVE-2022-22045 | Windows.Devices.Picker.dll Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Media | - | - | - |
| CVE-2022-22047 | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Client/Server Runtime Subsystem | Yes | - | - |
| CVE-2022-22048 | BitLocker Security Feature Bypass Vulnerability | Important | 6.1 |
Windows BitLocker | - | - | - |
| CVE-2022-22049 | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Client/Server Runtime Subsystem | - | - | - |
| CVE-2022-22050 | Windows Fax Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Fax and Scan Service | - | - | - |
| CVE-2022-33632 | Microsoft Office Security Feature Bypass Vulnerability | Important | 4.7 |
Microsoft Office | - | - | - |
| CVE-2022-33633 | Skype for Business and Lync Remote Code Execution Vulnerability | Important | 7.2 |
Skype for Business and Microsoft Lync | - | - | - |
| CVE-2022-33644 | Xbox Live Save Service Elevation of Privilege Vulnerability | Important | 7 |
XBox | - | - | - |
| CVE-2022-33650 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 4.9 |
Azure Site Recovery | - | - | - |
| CVE-2022-33651 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 4.9 |
Azure Site Recovery | - | - | - |
| CVE-2022-33652 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 4.9 |
Azure Site Recovery | - | - | - |
| CVE-2022-33653 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 4.9 |
Azure Site Recovery | - | - | - |
| CVE-2022-33654 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 4.9 |
Azure Site Recovery | - | - | - |
| CVE-2022-33655 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 6.5 |
Azure Site Recovery | - | - | - |
| CVE-2022-33656 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 6.5 |
Azure Site Recovery | - | - | - |
| CVE-2022-33657 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 6.5 |
Azure Site Recovery | - | - | - |
| CVE-2022-33658 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 4.9 |
Azure Site Recovery | - | - | - |
| CVE-2022-33659 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 4.9 |
Azure Site Recovery | - | - | - |
| CVE-2022-33660 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 4.9 |
Azure Site Recovery | - | - | - |
| CVE-2022-33661 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 6.5 |
Azure Site Recovery | - | - | - |
| CVE-2022-33662 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 6.5 |
Azure Site Recovery | - | - | - |
| CVE-2022-33663 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 6.5 |
Azure Site Recovery | - | - | - |
| CVE-2022-33664 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 4.9 |
Azure Site Recovery | - | - | - |
| CVE-2022-33665 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 6.5 |
Azure Site Recovery | - | - | - |
| CVE-2022-33666 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 6.5 |
Azure Site Recovery | - | - | - |
| CVE-2022-33667 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 6.5 |
Azure Site Recovery | - | - | - |
| CVE-2022-33668 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 4.9 |
Azure Site Recovery | - | - | - |
| CVE-2022-33669 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 4.9 |
Azure Site Recovery | - | - | - |
| CVE-2022-33671 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 4.9 |
Azure Site Recovery | - | - | - |
| CVE-2022-33672 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 6.5 |
Azure Site Recovery | - | - | - |
| CVE-2022-33673 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 6.5 |
Azure Site Recovery | - | - | - |
| CVE-2022-33674 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 8.3 |
Azure Site Recovery | - | - | - |
| CVE-2022-33675 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 7.8 |
Azure Site Recovery | - | - | - |
| CVE-2022-33676 | Azure Site Recovery Remote Code Execution Vulnerability | Important | 7.2 |
Azure Site Recovery | - | - | - |
| CVE-2022-33677 | Azure Site Recovery Elevation of Privilege Vulnerability | Important | 7.2 |
Azure Site Recovery | - | - | - |
| CVE-2022-33678 | Azure Site Recovery Remote Code Execution Vulnerability | Important | 7.2 |
Azure Site Recovery | - | - | - |
| CVE-2022-35798 | Azure Arc Jumpstart Information Disclosure Vulnerability | Moderate | 3.3 |
Azure Arc Jumpstart | - | - | - |
Threat Categories 6
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 51 | - |
| Remote Code Execution | 12 | 4 |
| Information Disclosure | 9 | - |
| Denial of Service | 4 | - |
| Security Feature Bypass | 4 | - |
| Tampering | 2 | - |
Affected Products 34
| Product | CVEs | Exploited |
|---|---|---|
| Azure Site Recovery | 32 | - |
| Windows Print Spooler Components | 4 | - |
| Microsoft Graphics Component | 3 | - |
| Windows Advanced Local Procedure Call | 3 | - |
| Windows Client/Server Runtime Subsystem | 3 | 1 |
| Windows IIS | 3 | - |
| Windows Network File System | 3 | - |
| Role: Windows Fax Service | 2 | - |
| Role: Windows Hyper-V | 2 | - |
| Windows BitLocker | 2 | - |
| Windows Media | 2 | - |
| Azure Arc Jumpstart | 1 | - |
| Azure Storage Library | 1 | - |
| Microsoft Defender for Endpoint | 1 | - |
| Microsoft Office | 1 | - |
| Role: DNS Server | 1 | - |
| Skype for Business and Microsoft Lync | 1 | - |
| Windows Active Directory | 1 | - |
| Windows Boot Manager | 1 | - |
| Windows Connected Devices Platform Service | 1 | - |
| Windows Credential Guard | 1 | - |
| Windows Fast FAT Driver | 1 | - |
| Windows Fax and Scan Service | 1 | - |
| Windows Group Policy | 1 | - |
| Windows Kernel | 1 | - |
| Windows Performance Counters | 1 | - |
| Windows Point-to-Point Tunneling Protocol | 1 | - |
| Windows Portable Device Enumerator Service | 1 | - |
| Windows Remote Procedure Call Runtime | 1 | - |
| Windows Security Account Manager | 1 | - |
| Windows Server Service | 1 | - |
| Windows Shell | 1 | - |
| Windows Storage | 1 | - |
| XBox | 1 | - |