Security News > 2022 > October > It’s Patch Tuesday and still no fix for ProxyNotShell Microsoft Exchange holes
Let's start off with what Redmond didn't fix: two Exchange Server bugs dubbed ProxyNotShell that have been exploited by snoops as far back as August.
A month later, Zero Day Initiative purchased the bugs and disclosed them to Microsoft.
Details of an information disclosure bug in Microsoft Office, tracked as CVE-2022-41043, has been publicly disclosed, so patch that one next before Redmond has to list it as under active exploit.
While Microsoft says these are "Less likely to be exploited," and noted that for a successful exploit an attacker would need additional access, Immersive Labs' Director of Cyber Threat Research Kev Breen suggested patching these sooner than later.
Atlassian, Microsoft bugs on CISA's must-patch list after exploitation spree.
Despite Adobe's assurance that none of these bugs have been exploited in the wild, as ZDI noted: "Hard to imagine hard-coded credentials have existed in the product for so long without being discovered."
News URL
https://go.theregister.com/feed/www.theregister.com/2022/10/11/october_patch_tuesday/
Related news
- Microsoft November 2024 Patch Tuesday fixes 4 zero-days, 91 flaws (source)
- Microsoft November 2024 Patch Tuesday fixes 4 zero-days, 89 flaws (source)
- Microsoft slips Task Manager and processor count fixes into Patch Tuesday (source)
- Microsoft December 2024 Patch Tuesday fixes 1 exploited zero-day, 71 flaws (source)
- Microsoft holds last Patch Tuesday of the year with 72 gifts for admins (source)
- Patch Tuesday: Microsoft Patches One Actively Exploited Vulnerability, Among Others (source)
- November 2024 Patch Tuesday forecast: New servers arrive early (source)
- Microsoft Exchange adds warning to emails abusing spoofing flaw (source)
- Patch Tuesday: Four Critical Vulnerabilities Paved Over (source)
- Microsoft pulls Exchange security updates over mail delivery issues (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-10-11 | CVE-2022-41043 | Unspecified vulnerability in Microsoft Office and Office Long Term Servicing Channel Microsoft Office Information Disclosure Vulnerability | 3.3 |