Patch Tuesday Archive
Patch Tuesday September 2022
Total CVEs
66
Critical
7
Important
58
Exploited
3
Publicly Disclosed
2
All CVEs this month 66
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2022-26928 | Windows Photo Import API Elevation of Privilege Vulnerability | Important | 7 |
Windows Photo Import API | - | - | - |
| CVE-2022-26929 | .NET Framework Remote Code Execution Vulnerability | Important | 7.8 |
.NET Framework | - | - | - |
| CVE-2022-30196 | Windows Secure Channel Denial of Service Vulnerability | Important | 8.2 |
Windows Transport Security Layer (TLS) | - | - | - |
| CVE-2022-35803 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2022-35823 | Microsoft SharePoint Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2022-38008 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2022-38009 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2022-37961 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2022-37964 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2022-38013 | .NET Core and Visual Studio Denial of Service Vulnerability | Important | 7.5 |
.NET and Visual Studio | - | - | - |
| CVE-2022-30200 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 7.8 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2022-33647 | Windows Kerberos Elevation of Privilege Vulnerability | Important | 8.1 |
Windows Kerberos | - | - | - |
| CVE-2022-33679 | Windows Kerberos Elevation of Privilege Vulnerability | Important | 8.1 |
Windows Kerberos | - | - | - |
| CVE-2022-35805 | Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Dynamics | - | - | - |
| CVE-2022-34700 | Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Dynamics | - | - | - |
| CVE-2022-35828 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Defender | - | - | - |
| CVE-2022-35830 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.1 |
Windows Remote Procedure Call | - | - | - |
| CVE-2022-35831 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | Important | 5.5 |
Windows Remote Access Connection Manager | - | - | - |
| CVE-2022-35832 | Windows Event Tracing Denial of Service Vulnerability | Important | 5.5 |
Windows Event Tracing | - | - | - |
| CVE-2022-35833 | Windows Secure Channel Denial of Service Vulnerability | Important | 7.5 |
Windows Transport Security Layer (TLS) | - | - | - |
| CVE-2022-35834 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Windows OLE DB | - | - | - |
| CVE-2022-35835 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Windows OLE DB | - | - | - |
| CVE-2022-35836 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Windows OLE DB | - | - | - |
| CVE-2022-35837 | Windows Graphics Component Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-35838 | HTTP V3 Denial of Service Vulnerability | Important | 7.5 |
Windows HTTP.sys | - | - | - |
| CVE-2022-35840 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Windows OLE DB | - | - | - |
| CVE-2022-35841 | Windows Enterprise App Management Service Remote Code Execution Vulnerability | Important | 8.8 |
Windows Enterprise App Management | - | - | - |
| CVE-2022-34718 | Windows TCP/IP Remote Code Execution Vulnerability | Critical | 9.8 |
Windows TCP/IP | - | - | - |
| CVE-2022-34719 | Windows Distributed File System (DFS) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Distributed File System (DFS) | - | - | - |
| CVE-2022-34720 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | Important | 7.5 |
Windows IKE Extension | - | - | - |
| CVE-2022-34721 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | Critical | 9.8 |
Windows IKE Extension | - | - | Yes |
| CVE-2022-34722 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | Critical | 9.8 |
Windows IKE Extension | - | - | - |
| CVE-2022-34723 | Windows DPAPI (Data Protection Application Programming Interface) Information Disclosure Vulnerability | Important | 5.5 |
Windows DPAPI (Data Protection Application Programming Interface) | - | - | - |
| CVE-2022-34724 | Windows DNS Server Denial of Service Vulnerability | Important | 7.5 |
Role: DNS Server | - | - | - |
| CVE-2022-34725 | Windows ALPC Elevation of Privilege Vulnerability | Important | 7 |
Windows ALPC | - | - | - |
| CVE-2022-34726 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Important | 8.8 |
Windows ODBC Driver | - | - | - |
| CVE-2022-34727 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Important | 8.8 |
Windows ODBC Driver | - | - | - |
| CVE-2022-34728 | Windows Graphics Component Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-34729 | Windows GDI Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-34730 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Important | 8.8 |
Windows ODBC Driver | - | - | - |
| CVE-2022-34731 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Windows OLE DB | - | - | - |
| CVE-2022-34732 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Important | 8.8 |
Windows ODBC Driver | - | - | - |
| CVE-2022-34733 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
Windows OLE DB | - | - | - |
| CVE-2022-34734 | Microsoft ODBC Driver Remote Code Execution Vulnerability | Important | 8.8 |
Windows ODBC Driver | - | - | - |
| CVE-2022-37954 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-37955 | Windows Group Policy Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Group Policy | - | - | - |
| CVE-2022-37956 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2022-38004 | Windows Fax Service Remote Code Execution Vulnerability | Important | 7.8 |
Role: Windows Fax Service | - | - | - |
| CVE-2022-37957 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2022-38005 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Print Spooler Components | - | - | - |
| CVE-2022-38006 | Windows Graphics Component Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-37959 | Network Device Enrollment Service (NDES) Security Feature Bypass Vulnerability | Important | 6.5 |
Network Device Enrollment Service (NDES) | - | - | - |
| CVE-2022-38007 | Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability | Important | 7.8 |
Azure Arc | - | - | - |
| CVE-2022-30170 | Windows Credential Roaming Service Elevation of Privilege Vulnerability | Important | 7.3 |
Windows Credential Roaming Service | - | - | - |
| CVE-2022-38010 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2022-37962 | Microsoft PowerPoint Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2022-38011 | Raw Image Extension Remote Code Execution Vulnerability | Important | 7.3 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2022-37963 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2022-37958 | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | Critical | 8.1 |
Windows SPNEGO Extended Negotiation | - | - | - |
| CVE-2022-38012 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Low | 7.7 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-37969 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | Yes | Yes | Yes |
| CVE-2022-38019 | AV1 Video Extension Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2022-37972 | Microsoft Endpoint Configuration Manager Spoofing Vulnerability | Important | 7.5 |
Microsoft Endpoint Configuration Manager | - | Yes | - |
| CVE-2022-38020 | Visual Studio Code Elevation of Privilege Vulnerability | Important | 7.3 |
Visual Studio Code | - | - | - |
| CVE-2022-41040 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Critical | 8.8 |
Microsoft Exchange Server | Yes | - | - |
| CVE-2022-41082 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 8 |
Microsoft Exchange Server | Yes | - | - |
Threat Categories 6
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 33 | 6 |
| Elevation of Privilege | 19 | 1 |
| Denial of Service | 7 | - |
| Information Disclosure | 5 | - |
| Security Feature Bypass | 1 | - |
| Spoofing | 1 | - |
Affected Products 39
| Product | CVEs | Exploited |
|---|---|---|
| Windows OLE DB | 6 | - |
| Microsoft Graphics Component | 5 | - |
| Windows ODBC Driver | 5 | - |
| Microsoft Office SharePoint | 4 | - |
| Windows IKE Extension | 3 | - |
| Windows Kernel | 3 | - |
| Microsoft Dynamics | 2 | - |
| Microsoft Exchange Server | 2 | 2 |
| Microsoft Office Visio | 2 | - |
| Microsoft Windows Codecs Library | 2 | - |
| Windows Common Log File System Driver | 2 | 1 |
| Windows Kerberos | 2 | - |
| Windows Transport Security Layer (TLS) | 2 | - |
| .NET Framework | 1 | - |
| .NET and Visual Studio | 1 | - |
| Azure Arc | 1 | - |
| Microsoft Edge (Chromium-based) | 1 | - |
| Microsoft Endpoint Configuration Manager | 1 | - |
| Microsoft Office | 1 | - |
| Network Device Enrollment Service (NDES) | 1 | - |
| Role: DNS Server | 1 | - |
| Role: Windows Fax Service | 1 | - |
| Visual Studio Code | 1 | - |
| Windows ALPC | 1 | - |
| Windows Credential Roaming Service | 1 | - |
| Windows DPAPI (Data Protection Application Programming Interface) | 1 | - |
| Windows Defender | 1 | - |
| Windows Distributed File System (DFS) | 1 | - |
| Windows Enterprise App Management | 1 | - |
| Windows Event Tracing | 1 | - |
| Windows Group Policy | 1 | - |
| Windows HTTP.sys | 1 | - |
| Windows LDAP - Lightweight Directory Access Protocol | 1 | - |
| Windows Photo Import API | 1 | - |
| Windows Print Spooler Components | 1 | - |
| Windows Remote Access Connection Manager | 1 | - |
| Windows Remote Procedure Call | 1 | - |
| Windows SPNEGO Extended Negotiation | 1 | - |
| Windows TCP/IP | 1 | - |