• Zine
  • Anonymous
  • Green
  • IT
  • Gadgets
  • Tech
  • Cloud
  • Data
  • Network
  • Security
  • Hosting
    • Sunset Host Co
    • Radio Host Co
  • Media
    • WSCA News
    • Sunset Crypto
    • Sustainable Action Now
    • Life.Style Magazine
    • Sunset Daily
    • Sunset Music News
    • Pro Merch Sports News
    • Explore New Jersey
    • Explore NJ News
    • The Zine Weekly
Facebook Twitter Instagram
Thursday, May 12
Facebook Twitter Instagram
The Zine Weekly
  • Zine

    Microsoft corrects Windows zero-day for May Patch Tuesday

    May 12, 2022

    Otago University bomb threat: Woman sent hoax to hide failure from parents

    May 12, 2022

    The emerging technologies that shape the financial industry

    May 12, 2022

    BMW looks to quantum computers to speed car design • The Register

    May 12, 2022

    EU Plan to Scan Private Messages for Child Abuse Images Puts Encryption at Risk

    May 12, 2022
  • Anonymous

    Anonymous appears to slam Elon Musk’s ‘left wing bias’ comment with new Twitter post

    May 11, 2022

    FACTBOX-The cyber war between Ukraine and Russia

    May 11, 2022

    CIA Expert Decodes Why Russia Which Even Hacked Into US Power Grids Is Failing In Cyber War In Ukraine

    May 10, 2022

    Anti-War Activists Stage ‘Guerrilla’ Protests on Victory Day

    May 9, 2022

    Deepfakes and espionage, but no cyber apocalypse from Vladimir Putin’s invasion

    May 9, 2022
  • Green

    Emerging hydrogen storage technology could increase energy resilience

    May 11, 2022

    Microgrid demo to lend a helping hand in India’s green energy transition

    May 9, 2022

    California prepares for energy shortfalls in hot, dry summer

    May 7, 2022

    Cryptocurrency’s dirty secret: Energy consumption

    May 5, 2022

    Stellantis pours billions more into Canada, electric

    May 3, 2022
  • IT

    Microsoft corrects Windows zero-day for May Patch Tuesday

    May 12, 2022

    WebCitz.com Announces Plans to Offer Free Web Hosting for Non-Profit Churches

    May 11, 2022

    How will VR collaboration transform meetings?

    May 10, 2022

    New Windows 11 preview makes Microsoft accounts mandatory for (almost) all

    May 9, 2022

    Announcing Reliable VPS Server Hosting Provider with Malaysia, Kuala Lumpur, Teluk Intan based IP – TheServerHost

    May 9, 2022
  • Gadgets

    How Apple’s music player transformed an industry

    May 12, 2022

    KuCoin Crypto Exchange Raises $150 Million in Funding, Plans to Launch Crypto Wallet, NFT Site

    May 11, 2022

    New tool shows homeowners and renters the true cost of disasters

    May 10, 2022

    iPhone 12, iPhone 12 Mini on Sale With Up to Rs. 11,910 Discount via Amazon India, Flipkart

    May 9, 2022

    Portable fluorescent probe identifies bad cooking oil

    May 9, 2022
  • Tech

    4D composite printing could improve the wings of drones

    May 11, 2022

    How to delete unused styles using VBA in Word

    May 9, 2022

    Best Gas Credit Cards in May 2022

    May 6, 2022

    Eshoo faces rivals from left, right and center in bid to retain Congress seat | News

    May 4, 2022

    Netflix cancels Meghan Markle animated series Pearl

    May 2, 2022
  • Cloud

    BMW looks to quantum computers to speed car design • The Register

    May 12, 2022

    Alkira launches free tool to tame cloud bloat

    May 11, 2022

    Ministry working to mitigate Merauke-Timika sea cable disruption

    May 10, 2022

    Cisco releases its Cloud Controls Framework to the public

    May 10, 2022

    Data Governance Market Collaborations Provide Effective And Impactful Solutions – IT Industry Today

    May 9, 2022
  • Data

    Asia-Africa-Europe-1 submarine cable system to add Infinera’s ICE6

    May 10, 2022

    Russia’s invasion of Ukraine could hurt Europe IT outsourcing

    May 10, 2022

    Insider Tips for Automating Analytics

    May 9, 2022

    CSPi to Announce Fiscal Second Quarter Financial Results on

    May 8, 2022

    AAON (NASDAQ:AAON) Posts Quarterly Earnings Results, Beats Estimates By $0.06 EPS

    May 8, 2022
  • Network

    The emerging technologies that shape the financial industry

    May 12, 2022

    Socket lands $4.6M to audit and catch malicious open-source code – TechCrunch

    May 11, 2022

    Keto Start ACV Gummies -WARNING: Shocking Reported About Side Effects? Job – 101 ARW ANG

    May 10, 2022

    Visualization analysis of sEMG | JPR

    May 10, 2022

    Beware: This cheap and ‘homemade’ malware is surprisingly effective

    May 9, 2022
  • Security

    Otago University bomb threat: Woman sent hoax to hide failure from parents

    May 12, 2022

    There’s Now A Hack To Get Apple CarPlay & Android Auto On Your Tesla

    May 11, 2022

    Alberta Court of Appeal to rule whether federal assessment law is unconstitutional

    May 10, 2022

    Manchin says he’d pass parts of Biden’s agenda. But Democrats may have to write the bill for him.

    May 8, 2022

    Work from home hack to make your cat think it can distract you, is a must-watch | Trending

    May 8, 2022
  • Hosting
    1. Sunset Host Co
    2. Radio Host Co
    Featured

    EU Plan to Scan Private Messages for Child Abuse Images Puts Encryption at Risk

    By Sunset Host CoMay 12, 20220
    Recent

    EU Plan to Scan Private Messages for Child Abuse Images Puts Encryption at Risk

    May 12, 2022

    Ransomware attack prompts response from Oregon election officials

    May 11, 2022

    Announcing Reliable VPS Server Hosting Provider with Netherlands, NL, Amsterdam based IP – TheServerHost – IT Industry Today

    May 10, 2022
  • Media
    1. WSCA News
    2. Sunset Crypto
    3. Sustainable Action Now
    4. Life.Style Magazine
    5. Sunset Daily
    6. Sunset Music News
    7. Pro Merch Sports News
    8. Explore New Jersey
    9. Explore NJ News
    10. The Zine Weekly
    Featured
    Recent

    Microsoft corrects Windows zero-day for May Patch Tuesday

    May 12, 2022

    Otago University bomb threat: Woman sent hoax to hide failure from parents

    May 12, 2022

    The emerging technologies that shape the financial industry

    May 12, 2022
The Zine Weekly
You are at:Home » Microsoft corrects Windows zero-day for May Patch Tuesday
IT News

Microsoft corrects Windows zero-day for May Patch Tuesday

Sunset Host CoBy Sunset Host CoMay 12, 2022No Comments6 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

Administrators who already have a Windows zero-day and a public disclosure to deal with will have to tread carefully when applying the May Patch Tuesday security updates.

Microsoft delivered several fixes concentrated in multiple hotspots that will require administrators to test systems thoroughly to avoid any headaches from faulty patches. Microsoft released 73 unique new CVEs for May Patch Tuesday, with six rated critical. The company reissued three CVEs to cover additional products and distributed one advisory to raise the number of total CVEs to 77.

Windows zero-day and a public disclosure top the May Patch Tuesday list

The zero-day is a Windows Local Security Authority (LSA) spoofing vulnerability (CVE-2022-26925) rated important for affected Windows client and server systems. LSA handles the validation of user sign-ins and implements security policies.

In addition to being actively exploited in the wild before a security update was available, this bug had been publicly disclosed. The Common Vulnerability Scoring System (CVSS) score is 8.1, but Microsoft said the CVSS score could increase to 9.8 if an attacker chains this vulnerability to an NTLM relay attack, commonly referred to as a man-in-the-middle attack, on Active Directory Certificate Services servers.

Chris Goettl

“The exploit is complicated to execute. The attacker needs to be in the environment and needs to interject themselves into that communication chain,” said Chris Goettl, vice president of product management at Ivanti, an IT asset and endpoint management company. “But if they do, it’s a pretty serious ability to spoof the security within that LSA communication chain.”

Administrators should refer to the KB5005413 article Microsoft published in 2021 to blunt the PetitPotam NTLM relay attack and execute some of its mitigations, such as Server Block Message (SMB) signing and enabling Extended Protection for Authentication on servers running Active Directory Certificate Services.

“Microsoft’s guidance in the specific update is to prioritize domain controllers to get the OS update quickly, because that’s where the focus of this particular exploit has occurred in the wild,” Goettl said.

The other publicly disclosed vulnerability is CVE-2022-22713, a Windows Hyper-V denial-of-service bug rated important that affects several Windows 10 versions (20H2, 21H1 and 21H2) and Windows Server version 20H2 Server Core installations. Despite the relatively low CVSS score of 5.6, the CVE should be considered dangerous because there is proof-of-concept code.

“Due to the fact that it has been publicly disclosed and there’s code samples available, much of the work of figuring out how to attack this vulnerability has been done. Now all they need to do is weaponize it,” Goettl said.

Other security updates of note for May Patch Tuesday include:

  • A fix for an Exchange Server vulnerability, an elevation-of-privilege flaw (CVE-2022-21978) rated important for supported Exchange products. The CVSS score is 8.1, and Microsoft provided extensive notes on the steps administrators need to execute to fully harden systems against this vulnerability.
  • Corrections for multiple vulnerabilities in three areas of the Windows OS:
    • four print spooler vulnerabilities (CVE-2022-29104, CVE-2022-29114, CVE-2022-29132 and CVE-2022-29140)
    • 10 Windows LDAP remote-code execution bugs (CVE-2022-22012, CVE-2022-22013, CVE-2022-22014, CVE-2022-29128, CVE-2022-29129, CVE-2022-29130, CVE-2022-29131, CVE-2022-29137, CVE-2022-29139 and CVE-2022-29141)
    • eight cluster shared volume flaws (CVE-2022-29134, CVE-2022-29135, CVE-2022-29138, CVE-2022-29120, CVE-2022-29122, CVE-2022-29123, CVE-2022-29150 and CVE-2022-29151)

Goettl recommended that administrators spend extra time to test the functionality related to the patched areas due to the high number of fixes.

Multiple Microsoft products reach the end of the road

Several Windows products received their last update on May Patch Tuesday. Windows 10 Enterprise and Education 1909, Windows 10 Home and Pro 20H2, and Windows Datacenter and Standard Server 20H2 hit their end-of-service date. Microsoft will not issue further security or quality updates for devices that run those branches.  

“If anybody has any remaining systems running those systems, they are now a liability. This is this is the time to go and clean those up and move them to newer branches,” Goettl said.

Microsoft plans to retire the Internet Explorer 11 browser on June 15 for Windows 10 systems and recommends customers use the Internet Explorer mode in Microsoft Edge if they need legacy support.  Prompts in Windows will nudge users to Microsoft Edge, and Microsoft will eventually disable the browser via Windows Update.

“People need to get Edge deployed, get compatibility mode turned on, and make sure that it’s working OK with their applications,” Goettl said.

Microsoft changes cumulative update model for Exchange Server

Outside of the Patch Tuesday news, Microsoft recently refined its servicing model for two major software products.

Along with news that Windows Server 2022 was generally available in September, the company said it would discontinue the semi-annual channel — which received two feature releases a year — for the server OS, leaving just the long-term servicing channel, which issues a feature release every two or three years.

On April 20, Microsoft said it would scale back its cumulative update schedule for Exchange Server. The company had been issuing quarterly releases, which typically arrived in March, June, September and December. The company said customers found the releases came too frequently and made it difficult to stay current.

“We are moving to a release cadence of two CUs [cumulative updates] per year — releasing in H1 and H2 of each calendar year, with general target release dates of March and September. But our release dates are driven by quality, so we might release updates in April or October, or some other month, depending on what we’re delivering,” the Exchange Team wrote in a blog.

Because Exchange 2013 and Exchange 2016 are out of mainstream support, only Exchange 2019 will receive the next cumulative update in the second half of this year. The earlier Exchange products will continue to receive security updates “as needed” while in extended support, the company said.

Microsoft’s lack of communication related to the on-premises messaging platform continues to vex Exchange administrators. Until Microsoft released the cumulative update blog, administrators had been waiting for the next cumulative update, which was due in December, to arrive.

Also, the next version of Exchange Server remains a mystery. In September 2020, Microsoft said Exchange vNext would arrive in the second half of 2021, but the product remains in limbo along with Skype for Business Server and SharePoint Server.

“Are we going to see an on-prem Exchange Server or will Microsoft pull a fast one and do a hosted Exchange Server, like an Azure Exchange?” Goettl said.

Share this:

  • Twitter
  • Facebook

Related

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleOtago University bomb threat: Woman sent hoax to hide failure from parents
Sunset Host Co
  • Website
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • Tumblr
  • LinkedIn

Related Posts

WebCitz.com Announces Plans to Offer Free Web Hosting for Non-Profit Churches

May 11, 2022

How will VR collaboration transform meetings?

May 10, 2022

New Windows 11 preview makes Microsoft accounts mandatory for (almost) all

May 9, 2022

Comments are closed.

Categories
  • Anonymous (92)
  • Cloud (146)
  • Data Center (128)
  • Gadgets (167)
  • Green Tech (37)
  • Hosting solutions (90)
  • IT News (91)
  • Network (136)
  • Security (129)
  • Tech (95)
  • Web hosting (58)
  • Zine
  • Anonymous
  • Green
  • IT
  • Gadgets
  • Tech
  • Cloud
  • Data
  • Network
  • Security
  • Hosting
    • Sunset Host Co
    • Radio Host Co
  • Media
    • WSCA News
    • Sunset Crypto
    • Sustainable Action Now
    • Life.Style Magazine
    • Sunset Daily
    • Sunset Music News
    • Pro Merch Sports News
    • Explore New Jersey
    • Explore NJ News
    • The Zine Weekly

Subscribe to Updates

Get the latest tech news from the Zine at the Sunset Host Co. and the Radio Host Co.

Microsoft corrects Windows zero-day for May Patch Tuesday

May 12, 2022

Otago University bomb threat: Woman sent hoax to hide failure from parents

May 12, 2022

The emerging technologies that shape the financial industry

May 12, 2022

BMW looks to quantum computers to speed car design • The Register

May 12, 2022

EU Plan to Scan Private Messages for Child Abuse Images Puts Encryption at Risk

May 12, 2022

How Apple’s music player transformed an industry

May 12, 2022

Emerging hydrogen storage technology could increase energy resilience

May 11, 2022

Anonymous appears to slam Elon Musk’s ‘left wing bias’ comment with new Twitter post

May 11, 2022
Copyright © 2022. The Zine Weekly, an SCA Entertainment & Media Company. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.