Security News > 2022 > July > Microsoft's July Patch Tuesday fixes actively exploited bug
![Microsoft's July Patch Tuesday fixes actively exploited bug](/static/build/img/news/microsoft-s-july-patch-tuesday-fixes-actively-exploited-bug-medium.jpg)
Despite worries that Patch Tuesday may not be as exciting now that Microsoft's Windows Autopatch is live - with a slew of caveats - the second Tuesday of this month arrived with 84 security fixes, including 4 critical bugs and one that's under active exploit.
Microsoft deemed it an "Important" security issue, with low complexity and low privileges required to exploit.
While the July fixes received a lower CVSS score compared to previous months' - the latest ones received 8.1 and 7.5 severity scores, respectively, compared to last month's 9.8 CVSS rating - as with the earlier NFS bugs, they could be exploited over the network by a unauthenticated attacker and used to remotely execute malicious code.
CVE-2022-20812 is a flaw in the cluster database API of Cisco Expressway Series and Cisco TelePresence VCS. "An attacker could exploit this vulnerability by authenticating to the system as an administrative read-write user and submitting crafted input to the affected command," according to the security advisory.
"A successful exploit could allow the attacker to overwrite arbitrary files on the underlying operating system as the root user."
Roid fixes critical RCE. And finally, Google issued 27 fixes for Android devices in its July security bulletin.
News URL
https://go.theregister.com/feed/www.theregister.com/2022/07/12/microsoft_july_patch_tuesday/
Related news
- What Is Patch Tuesday? Microsoft’s Monthly Update Explained (source)
- Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws (source)
- January 2025 Patch Tuesday forecast: Changes coming in cybersecurity guidance (source)
- Week in review: Exploited Ivanti Connect Secure zero-day, Patch Tuesday forecast (source)
- Patch Tuesday: January 2025 Security Update Patches Exploited Elevation of Privilege Attacks (source)
- Windows Patch Tuesday hits snag with Citrix software, workarounds published (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-07-06 | CVE-2022-20812 | Path Traversal vulnerability in Cisco Telepresence Video Communication Server Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device. | 6.5 |