Security
Headlines
HeadlinesLatestCVEs

Source

Microsoft Security Response Center

CVE-2022-21992: Windows Mobile Device Management Remote Code Execution Vulnerability

**According to the CVSS score, the attack vector is Local. Why does the CVE title indicate that this is a Remote Code Execution?** The word **Remote** in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. For example, when the score indicates that the **Attack Vector** is **Local** and **User Interaction** is **Required**, this could describe an exploit in which an attacker, through social engineering, convinces a victim to download and open a specially crafted file from a website which leads to a local attack on their computer.

Microsoft Security Response Center
#vulnerability#web#windows#Windows Kernel#Security Vulnerability
CVE-2022-21986: .NET Denial of Service Vulnerability

**What .NET component is affected by this denial of service vulnerability?** This vulnerability affects applications that utilize the Kestrel web server when processing certain HTTP/2 and HTTP/3 requests.

CVE-2022-21995: Windows Hyper-V Remote Code Execution Vulnerability

**What is meant by scope change for this particular vulnerability?** In this case, a successful attack could be performed from a low privilege Hyper-V guest. The attacker could traverse the guest's security boundary to execute code on the Hyper-V host execution environment.

CVE-2022-21991: Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability

**Why is Attack Complexity marked as High for this vulnerability?** Successful exploitation of this vulnerability requires an attacker to gather information specific to environment of the targeted component.

CVE-2022-21957: Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability

**Are the updates for the Microsoft Dynamics 365 (on-premises) versions listed in this vulnerability currently available?** The security update for Microsoft Dynamics 365 (on-premises) version 8.2 and Microsoft Dynamics 365 (on-premises) version 9.1 are not immediately available. The updates will be released as soon as possible, and when they are available, customers will be notified via a revision to this CVE information.

CVE-2022-23263: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

**What is the version information for this release?** Microsoft Edge Version Date Released Based on Chromium Version 98.0.1108.43 2/3/2022 98.0.4758.80

CVE-2022-23262: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

**What is the version information for this release?** Microsoft Edge Version Date Released Based on Chromium Version 98.0.1108.43 2/3/2022 98.0.4758.80

CVE-2022-23261: Microsoft Edge (Chromium-based) Tampering Vulnerability

**What is the version information for this release?** Microsoft Edge Version Date Released Based on Chromium Version 98.0.1108.43 2/3/2022 98.0.4758.80

CVE-2022-0470: Chromium: CVE-2022-0470 Out of bounds memory access in V8

**What is the version information for this release?** Microsoft Edge Version Date Released Based on Chromium Version 98.0.1108.43 2/3/2022 98.0.4758.80