Security News > 2022 > February > Microsoft and Other Major Software Firms Release February 2022 Patch Updates
Microsoft on Tuesday rolled out its monthly security updates with fixes for 51 vulnerabilities across its software line-up consisting of Windows, Office, Teams, Azure Data Explorer, Visual Studio Code, and other components such as Kernel and Win32k.
Among the 51 defects closed, 50 are rated Important and one is rated Moderate in severity, making it one of the rare Patch Tuesday updates without any fixes for Critical-rated vulnerabilities.
None of the security vulnerabilities are listed as under active exploit, while of the flaws - CVE-2022-21989 - has been classified as a publicly disclosed zero-day at the time of the release.
The security update also remediates a Azure Data Explorer spoofing vulnerability, two security bypass vulnerabilities each impacting Outlook for Mac and OneDrive for Android, and two denial-of-service vulnerabilities in.
The updates arrive as the tech giant late last month republished a vulnerability dating back to 2013 - a signature validation issue affecting WinVerifyTrust - noting that the fix is "Available as an opt-in feature via reg key setting, and is available on supported editions of Windows released since December 10, 2013.".
Security updates have also been released by other vendors to rectify several vulnerabilities, counting -.
News URL
https://thehackernews.com/2022/02/microsoft-and-other-major-software.html
Related news
- Microsoft October 2024 Patch Tuesday fixes 5 zero-days, 118 flaws (source)
- Microsoft cleans up hot mess of Patch Tuesday preview (source)
- Microsoft SharePoint RCE flaw exploits in the wild – you've had 3 months to patch (source)
- Microsoft November 2024 Patch Tuesday fixes 4 zero-days, 91 flaws (source)
- Microsoft November 2024 Patch Tuesday fixes 4 zero-days, 89 flaws (source)
- Microsoft slips Task Manager and processor count fixes into Patch Tuesday (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-02-09 | CVE-2022-21989 | Unspecified vulnerability in Microsoft products Windows Kernel Elevation of Privilege Vulnerability | 0.0 |