Patch Tuesday Archive
Patch Tuesday December 2022
Total CVEs
52
Critical
6
Important
42
Exploited
1
Publicly Disclosed
1
All CVEs this month 52
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2022-41127 | Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability | Critical | 8.5 |
Microsoft Dynamics | - | - | - |
| CVE-2022-44666 | Windows Contacts Remote Code Execution Vulnerability | Important | 7.8 |
Windows Contacts | - | - | - |
| CVE-2022-44667 | Windows Media Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2022-44668 | Windows Media Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2022-44673 | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | Important | 7 |
Client Server Run-time Subsystem (CSRSS) | - | - | - |
| CVE-2022-44674 | Windows Bluetooth Driver Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Bluetooth Driver | - | - | - |
| CVE-2022-44675 | Windows Bluetooth Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Bluetooth Driver | - | - | - |
| CVE-2022-44676 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Secure Socket Tunneling Protocol (SSTP) | - | - | - |
| CVE-2022-44677 | Windows Projected File System Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Projected File System | - | - | - |
| CVE-2022-44678 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows HTTP Print Provider | - | - | - |
| CVE-2022-44679 | Windows Graphics Component Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-44680 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-44681 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Print Spooler Components | - | - | - |
| CVE-2022-44682 | Windows Hyper-V Denial of Service Vulnerability | Important | 6.8 |
Role: Windows Hyper-V | - | - | - |
| CVE-2022-44683 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2022-44688 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Moderate | 4.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-44690 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2022-44691 | Microsoft Office OneNote Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office OneNote | - | - | - |
| CVE-2022-44692 | Microsoft Office Graphics Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2022-44693 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2022-44694 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2022-44695 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2022-44696 | Microsoft Office Visio Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Visio | - | - | - |
| CVE-2022-44697 | Windows Graphics Component Elevation of Privilege Vulnerability | Moderate | 7.8 |
Microsoft Graphics Component | - | - | - |
| ADV220005 | Guidance on Microsoft Signed Drivers Being Used Maliciously | None | - | Windows Certificates | - | - | - |
| CVE-2022-44698 | Windows SmartScreen Security Feature Bypass Vulnerability | Moderate | 5.4 |
Windows SmartScreen | Yes | - | - |
| CVE-2022-44702 | Windows Terminal Remote Code Execution Vulnerability | Important | 7.8 |
Windows Terminal | - | - | - |
| CVE-2022-44704 | Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability | Important | 7.8 |
SysInternals | - | - | - |
| CVE-2022-44707 | Windows Kernel Denial of Service Vulnerability | Important | 6.5 |
Windows Kernel | - | - | - |
| CVE-2022-44708 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Important | 8.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-24480 | Outlook for Android Elevation of Privilege Vulnerability | Important | 6.3 |
Microsoft Office Outlook | - | - | - |
| CVE-2022-26804 | Microsoft Office Graphics Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-26805 | Microsoft Office Graphics Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-26806 | Microsoft Office Graphics Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-41089 | .NET Framework Remote Code Execution Vulnerability | Important | 7.8 |
.NET Framework | - | - | - |
| CVE-2022-41094 | Windows Hyper-V Elevation of Privilege Vulnerability | Important | 7.8 |
Role: Windows Hyper-V | - | - | - |
| CVE-2022-41074 | Windows Graphics Component Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-41076 | PowerShell Remote Code Execution Vulnerability | Critical | 8.5 |
Windows PowerShell | - | - | - |
| CVE-2022-41115 | Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability | Important | 6.6 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-41077 | Windows Fax Compose Form Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Fax Compose Form | - | - | - |
| CVE-2022-41121 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-44669 | Windows Error Reporting Elevation of Privilege Vulnerability | Important | 7 |
Windows Error Reporting | - | - | - |
| CVE-2022-44670 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Secure Socket Tunneling Protocol (SSTP) | - | - | - |
| CVE-2022-44671 | Windows Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-44687 | Raw Image Extension Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Codecs Library | - | - | - |
| CVE-2022-44689 | Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Subsystem for Linux | - | - | - |
| CVE-2022-44699 | Azure Network Watcher Agent Security Feature Bypass Vulnerability | Important | 5.5 |
Azure | - | - | - |
| CVE-2022-44710 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DirectX | - | Yes | - |
| CVE-2022-44713 | Microsoft Outlook for Mac Spoofing Vulnerability | Important | 7.5 |
Microsoft Office Outlook | - | - | - |
| CVE-2022-47211 | Microsoft Office Graphics Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-47212 | Microsoft Office Graphics Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-47213 | Microsoft Office Graphics Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
Threat Categories 7
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 23 | 6 |
| Elevation of Privilege | 18 | - |
| Denial of Service | 3 | - |
| Information Disclosure | 3 | - |
| Security Feature Bypass | 2 | - |
| Spoofing | 2 | - |
| Defense in Depth | 1 | - |
Affected Products 29
| Product | CVEs | Exploited |
|---|---|---|
| Microsoft Graphics Component | 12 | - |
| Microsoft Edge (Chromium-based) | 3 | - |
| Microsoft Office Visio | 3 | - |
| Microsoft Windows Codecs Library | 3 | - |
| Microsoft Bluetooth Driver | 2 | - |
| Microsoft Office Outlook | 2 | - |
| Microsoft Office SharePoint | 2 | - |
| Role: Windows Hyper-V | 2 | - |
| Windows Kernel | 2 | - |
| Windows Secure Socket Tunneling Protocol (SSTP) | 2 | - |
| .NET Framework | 1 | - |
| Azure | 1 | - |
| Client Server Run-time Subsystem (CSRSS) | 1 | - |
| Microsoft Dynamics | 1 | - |
| Microsoft Office | 1 | - |
| Microsoft Office OneNote | 1 | - |
| SysInternals | 1 | - |
| Windows Certificates | 1 | - |
| Windows Contacts | 1 | - |
| Windows DirectX | 1 | - |
| Windows Error Reporting | 1 | - |
| Windows Fax Compose Form | 1 | - |
| Windows HTTP Print Provider | 1 | - |
| Windows PowerShell | 1 | - |
| Windows Print Spooler Components | 1 | - |
| Windows Projected File System | 1 | - |
| Windows SmartScreen | 1 | 1 |
| Windows Subsystem for Linux | 1 | - |
| Windows Terminal | 1 | - |