Security News > 2022 > February > Microsoft and Other Major Software Firms Release February 2022 Patch Updates
Microsoft on Tuesday rolled out its monthly security updates with fixes for 51 vulnerabilities across its software line-up consisting of Windows, Office, Teams, Azure Data Explorer, Visual Studio Code, and other components such as Kernel and Win32k.
Among the 51 defects closed, 50 are rated Important and one is rated Moderate in severity, making it one of the rare Patch Tuesday updates without any fixes for Critical-rated vulnerabilities.
None of the security vulnerabilities are listed as under active exploit, while of the flaws - CVE-2022-21989 - has been classified as a publicly disclosed zero-day at the time of the release.
The security update also remediates a Azure Data Explorer spoofing vulnerability, two security bypass vulnerabilities each impacting Outlook for Mac and OneDrive for Android, and two denial-of-service vulnerabilities in.
The updates arrive as the tech giant late last month republished a vulnerability dating back to 2013 - a signature validation issue affecting WinVerifyTrust - noting that the fix is "Available as an opt-in feature via reg key setting, and is available on supported editions of Windows released since December 10, 2013.".
Security updates have also been released by other vendors to rectify several vulnerabilities, counting -.
News URL
https://thehackernews.com/2022/02/microsoft-and-other-major-software.html
Related news
- Microsoft says premature patch could make Windows Recall forget how to work (source)
- Microsoft December 2024 Patch Tuesday fixes 1 exploited zero-day, 71 flaws (source)
- Microsoft holds last Patch Tuesday of the year with 72 gifts for admins (source)
- Microsoft Fixes 72 Flaws, Including Patch for Actively Exploited CLFS Vulnerability (source)
- Patch Tuesday: Microsoft Patches One Actively Exploited Vulnerability, Among Others (source)
- What Is Patch Tuesday? Microsoft’s Monthly Update Explained (source)
- Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-02-09 | CVE-2022-21989 | Unspecified vulnerability in Microsoft products Windows Kernel Elevation of Privilege Vulnerability | 0.0 |