Two entries listed as critical are privilege escalation vulnerabilities in Windows Kerberos, according to Cisco Talos. Microsoft said exploitation of both is more likely. CVE-2022-37966 is a Windows Kerberos RC4-HMAC Elevation of Privilege and CVE-2022-37967 is a Windows Kerberos Elevation of Privilege Vulnerability.
CVE-2022-37966 is a privilege escalation vulnerability in Windows Kerberos, where an unauthenticated attacker may be able to leverage vulnerabilities in RFC 4757 (Kerberos encryption type RC4-HMAC-MD5) and MS-PAC (Privilege Attribute Certificate Data Structure specification) to bypass constrained delegation security features in a Windows AD environment. The attack complexity has been labeled as “High.”
CVE-2022-37967 is another privilege escalation vulnerability in Windows Kerberos, where an authenticated attacker could leverage cryptographic protocol vulnerabilities in the Windows Kerberos AES-SHA1 cipher suite. If an attacker is successful in gaining control over the service that is allowed for delegation, they can modify Kerberos PAC to elevate their privileges. In contrast to CVE-2022-37966, the attack complexity is considered “Low.”
Three of the critical entries (CVE-2022-41039, CVE-2022-41044, and CVE-2022-41088) are remote code execution (RCE) vulnerabilities for Windows Point-to-Point Tunneling Protocol (PPTP), according to a report with Cisco Talos.
An unauthenticated attacker can send a specially crafted request to an RAS (Remote Access Server), which may lead to remote code execution. Although according to Microsoft, these three vulnerabilities are less likely to be exploited, as the attacker must win a complex race condition. In August of 2022’s Patch Tuesday release, several vulnerabilities for Windows PPTP were also disclosed.
Another vulnerability CVE-2022-41118 is a remote code execution vulnerability for the JScript9 and Chakra scripting languages. While exploiting this vulnerability requires the attacker win a race condition, Microsoft determined that exploitation is more likely. Successful exploitation of CVE-2022-41118 requires the attacker convince the victim to visit a malicious server share or website. This requirement can likely be met by phishing emails or another form of social engineering.
Also listed in this release is CVE-2022-38015, a Windows Hyper-V denial of service vulnerability, according to Cisco Talos. This affects Windows 10 and 11 hosts, as well as Windows Server 2016 and 2022. While the attack complexity is listed as “Low,” Microsoft considers successful exploitation as “Less Likely.”
The last critical disclosure is CVE-2022-41080, a Microsoft Exchange Server elevation of privilege vulnerability, which has a low attack complexity and successful exploitation is considered “More Likely,” according to Cisco Talos. CVE-2022-41080 affects Microsoft Exchange Server versions:
- Microsoft Exchange Server 2013 Cumulative Update 23
- Microsoft Exchange Server 2016 Cumulative Update 22
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 11
- Microsoft Exchange Server 2019 Cumulative Update 12
Talos also highlighted three “Important” vulnerabilities as Microsoft listed them as being successfully exploited in the wild:
- CVE-2022-41091 — Windows Mark of the Web Security Feature Bypass Vulnerability
- CVE-2022-41073 — Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-41125 — Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
Click here for a complete list of all the vulnerabilities Microsoft disclosed this month.
In response to these vulnerability disclosures, Talos released a Snort rule set that detects attempts to exploit some of them.
The rules included in this release that protect against the exploitation of many of these vulnerabilities are 60815-60816, 60818-60819, 60820-60821, 60822-60823, 60831-60832, 60833-60834. For Snort 3, the following rules are also available to protect against these vulnerabilities: 300309, 300310, 300311, 300312, 300315, 300316.

