The Cyber Security Review | Monday, December 19, 2022
One moderate vulnerability that's already been exploited impacts the Windows SmartScreen Security Feature.
FREMONT, CA: Microsoft (NASDAQ: MSFT) revealed 56 vulnerabilities, including six severe flaws and one exploitable moderate flaw. In addition to Microsoft Windows and Windows Components, Azure, Office and Office Components, SysInternals, Microsoft Edge (Chromium-based), SharePoint Server, and the.NET framework also have vulnerabilities that the updates issued a fix. The Windows SmartScreen Security Feature is impacted by the exploited CVE that was revealed on Patch Tuesday. An attacker could create a malicious file to take advantage of it and get through Mark of the Web (MOTW) protections.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Windows appends the zone identifier, or MOTW, to the file when they download it from the internet. That MOTW requests a reputation check from Windows SmartScreen. The integrity and availability of security features that rely on MOTW tagging, including Protected View in Microsoft Office, are only slightly compromised due to this hack. A user would need to be persuaded to visit a malicious website or click on a malicious attachment for the attacker to be able to take advantage of the vulnerability.
All six significant CVEs involved Remote Code Execution (RCE) flaws. They affect Windows Secure Socket Tunneling Protocol, Microsoft SharePoint Server, Microsoft Dynamics NAV, and Microsoft Dynamics 365 Business Central (On-Premises) (SSTP).
Quality and Experience Updates
The KB5021255 update for computers running Windows 11 version 22H2 makes several adjustments to the Settings app. On the Systems page, there are new storage notifications for OneDrive members, and on the Personalization tab, Microsoft has integrated Windows Spotlight and Themes.
A new mobile device management (MDM) policy for business messages is also included in this patch. IT professionals may now deliver identical notifications to all managed Windows 11 PCs in an organisation thanks to a new capability in Windows 11 version 22H2.
The KB5021234 patch adds Microsoft's Quick Assist app to all client devices for Windows 11 users who are still using the OS version 21H2 of the operating system. Additionally, this upgrade gives enterprise clients a new approach to identify if joined Azure Active Directory devices are on a secure network by authenticating them. This capability must be enabled by IT administrators using a mobile device management (MDM) policy.
Cortana will be unpinned from the taskbar by the KB5021233 patch for Windows 10 versions 21H1, 21H2, and 22H2, while users can undo this change in taskbar settings. Additionally, on PCs with the taskbar at the top of the screen, the taskbar search box will now always be visible.
Before extensively installing this month's patches on production systems, organisations should thoroughly test them. However, given that hackers are already figuring out how to exploit recently discovered vulnerabilities, it is only advisable to implement the updates extensively.
A good practice is to back up systems before installing updates. Users have problems with Windows updates every month that result in systems that won't boot, problems with hardware and software compatibility, or even data loss in extreme circumstances.
More in News