🕵️ SicherheitslückenWeb Application Firewall Rule Bypass in Jetpack WAF Runtime(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenCross-Site Request Forgery in WooCommerce Product and Term Ordering(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenUnescaped Output in Enable Media Replace Error View(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenStored Cross-Site Scripting in WooCommerce Order Notes REST API v4(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenUnescaped Attribute Output in Enable Media Replace Upsell View(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenWeb Application Firewall Rule Bypass in Jetpack WAF Runtime(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenCross-Site Request Forgery in WooCommerce Product and Term Ordering(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenUnescaped Output in Enable Media Replace Error View(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenStored Cross-Site Scripting in WooCommerce Order Notes REST API v4(17.09.2026 um 16:34 Uhr)
🕵️ SicherheitslückenUnescaped Attribute Output in Enable Media Replace Upsell View(17.09.2026 um 16:34 Uhr)
🕵️ Hacking 🕛 vor 4 Jahren 20 Min Lesezeit CVE-2022-1125
0

The April 2022 Security Update Review

Cyber Threat & Vulnerability Dossier
ANGRIPPSVEKTOR
💻 Lokal
AUTHENTIFIZIERUNG
🔑 Geringe Nutzerrechte nötig
SCHADENSPROFIL
⛔ Dienstausfall (DoS) / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-119: Memory Corruption
Handlungsempfehlung: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
Im CVE-Radar öffnen
↗ Quelle (thezdi.com)
🔬 IoC Intelligence (145 Indikatoren erkannt)
CVE-2022-26809CVE-2022-24491CVE-2022-26815CVE-2022-26904CVE-2022-24521CVE-2022-23259CVE-2022-22008CVE-2022-23257+137 weitere
🗣️ Stimme:

Another Patch Tuesday is upon, and Adobe and Microsoft have released a bevy of new security updates. Take a break from your regularly scheduled activities and join us as we review the details of their latest security offerings.

Adobe Patches for April 2022

For April, Adobe released four updates addressing 70 CVEs in Acrobat and Reader, Photoshop, After Effects, and Adobe Commerce. The update for , and all of these were reported through the ZDI program. All the vulnerabilities addressed by this patch address Critical-rated code execution bugs. Again, an attacker would need to convince a user to open a specially crafted file to gain code execution.

The update for fixes a single, Critical-rated vulnerability. Adobe rates this as a CVSS 9.1, but they also point out authentication would be required to exploit this bug. They also note admin privileges are required, so the high CVSS is somewhat puzzling. Still, if you’re using Commerce, test and deploy this patch as soon as you are able.

None of the bugs fixed by Adobe this month are listed as publicly known or under active attack at the time of release.

Microsoft Patches for April 2022

This month, Microsoft released 128 new patches addressing CVEs in Microsoft Windows and Windows Components, Microsoft Defender and Defender for Endpoint, Microsoft Dynamics, Microsoft Edge (Chromium-based), Exchange Server, Office and Office Components, SharePoint Server, Windows Hyper-V, DNS Server, Skype for Business, .NET and Visual Studio, Windows App Store, and Windows Print Spooler Components. This is in addition to the 17 CVEs consumed from the Chromium Open-Source Software (OSS) by Microsoft Edge (Chromium-based), which brings the April total to 145 CVEs.

Of the 128 new CVEs released today, 10 are rated Critical, 115 are rated Important, and three are rated Moderate in severity. A total of six of these bugs came through the ZDI program. This large volume of patches hasn’t been seen since the fall of 2020. However, this level is similar to what we saw in the first quarter of last year.

One of the bugs patched is listed as under active exploit this month, and one other is listed as publicly known at the time of release. Let’s take a closer look at some of the more interesting updates for this month, starting with a Critical-rated bug that could prove wormable:

-       / - Windows DNS Server Remote Code Execution Vulnerability
This vulnerability is the most severe of the 18(!) DNS Server bugs receiving patches this month. This bug is also very similar to one - Windows User Profile Service Elevation of Privilege Vulnerability
This is one of the publicly known bugs patched this month, and not only is PoC out there for it, there’s a
Windows Common Log File System Driver
Elevation of Privilege Vulnerability
Important
7.8
No
Yes
EoP

Microsoft Dynamics 365 (on-premises) Remote
Code Execution Vulnerability
Critical
8.8
No
No
RCE

Windows Hyper-V Remote Code Execution
Vulnerability
Critical
7.7
No
No
RCE

Windows Hyper-V Remote Code Execution
Vulnerability
Critical
7.7
No
No
RCE

Windows Network File System Remote Code
Execution Vulnerability
Critical
9.8
No
No
RCE

Windows Server Service Remote Code Execution
Vulnerability
Critical
8.8
No
No
RCE

.NET Framework Denial of Service
Vulnerability
Important
7.5
No
No
DoS

Azure Site Recovery Elevation of Privilege
Vulnerability
Important
4.9
No
No
EoP

Azure Site Recovery Remote Code Execution
Vulnerability
Important
7.2
No
No
RCE

Connected User Experiences and Telemetry
Elevation of Privilege Vulnerability
Important
7.8
No
No
EoP

GitHub: Git for Windows' uninstaller
vulnerable to DLL hijacking when run under the SYSTEM user account
Important
Unknown
No
No
EoP

HEVC Video Extensions Remote Code Execution
Vulnerability
Important
7.8
No
No
RCE

Microsoft Defender Denial of Service
Vulnerability
Important
5.5
No
No
DoS

Microsoft Edge (Chromium-based) Elevation of
Privilege Vulnerability
Important
8.3
No
No
EoP

Microsoft Edge (Chromium-based) Elevation of
Privilege Vulnerability
Important
8.3
No
No
EoP

Microsoft Edge (Chromium-based) Elevation of
Privilege Vulnerability
Important
8.3
No
No
EoP

Microsoft Excel Remote Code Execution
Vulnerability
Important
7.8
No
No
RCE

Microsoft Local Security Authority (LSA)
Server Information Disclosure Vulnerability
Important
5.5
No
No
Info

Microsoft SharePoint Server Spoofing
Vulnerability
Important
8
No
No
Spoofing

Remote Desktop Protocol Remote Code
Execution Vulnerability
Important
8
No
No
RCE

Remote Procedure Call Runtime Remote Code
Execution Vulnerability
Important
8.8
No
No
RCE

Skype for Business Information Disclosure
Vulnerability
Important
6.5
No
No
Info

Visual Studio Elevation of Privilege
Vulnerability
Important
7.8
No
No
EoP

Win32 Stream Enumeration Remote Code
Execution Vulnerability
Important
7.5
No
No
RCE

Win32k Elevation of Privilege
Vulnerability
Important
7.8
No
No
EoP

Windows ALPC Elevation of Privilege
Vulnerability
Important
7
No
No
EoP

Windows AppX Package Manager Elevation of
Privilege Vulnerability
Important
7.8
No
No
EoP

Windows Cluster Shared Volume (CSV) Denial
of Service Vulnerability
Important
5.5
No
No
DoS

Windows Cluster Shared Volume (CSV) Denial
of Service Vulnerability
Important
6.5
No
No
DoS

Windows Desktop Bridge Elevation of
Privilege Vulnerability
Important
7.8
No
No
EoP

Windows Direct Show - Remote Code Execution
Vulnerability
Important
7
No
No
RCE

Windows DNS Server Remote Code Execution
Vulnerability
Important
7.2
No
No
RCE

Windows DNS Server Remote Code Execution
Vulnerability
Important
6.7
No
No
RCE

Windows DNS Server Remote Code Execution
Vulnerability
Important
7.5
No
No
RCE

Windows DNS Server Remote Code Execution
Vulnerability
Important
7.5
No
No
RCE

Windows DNS Server Remote Code Execution
Vulnerability
Important
6.6
No
No
RCE

Windows DNS Server Remote Code Execution
Vulnerability
Important
6.6
No
No
RCE

Windows DNS Server Remote Code Execution
Vulnerability
Important
7.2
No
No
RCE

Windows DNS Server Remote Code Execution
Vulnerability
Important
7.2
No
No
RCE

Windows DNS Server Remote Code Execution
Vulnerability
Important
7.5
No
No
RCE

Windows Endpoint Configuration Manager
Elevation of Privilege Vulnerability
Important
7.8
No
No
EoP

Windows Fax Compose Form Remote Code
Execution Vulnerability
Important
7.8
No
No
RCE

Windows File Explorer Elevation of Privilege
Vulnerability
Important
7
No
No
EoP

Windows File Server Resource Management
Service Elevation of Privilege Vulnerability
Important
7
No
No
EoP

Windows Graphics Component Remote Code
Execution Vulnerability
Important
7.8
No
No
RCE

Windows Hyper-V Remote Code Execution
Vulnerability
Important
7.7
No
No
RCE

Windows Hyper-V Shared Virtual Hard Disks
Information Disclosure Vulnerability
Important
8.1
No
No
Info

Windows Hyper-V Shared Virtual Hard Disks
Information Disclosure Vulnerability
Important
6.5
No
No
Info

Windows Installer Elevation of Privilege
Vulnerability
Important
7.8
No
No
EoP

Windows Kerberos Elevation of Privilege
Vulnerability
Important
7.8
No
No
EoP

Windows Kerberos Remote Code Execution
Vulnerability
Important
8.1
No
No
RCE

Windows LDAP Denial of Service
Vulnerability
Important
7.5
No
No
DoS

Windows Print Spooler Elevation of Privilege
Vulnerability
Important
7.8
No
No
EoP

Windows Print Spooler Elevation of Privilege
Vulnerability
Important
7.8
No
No
EoP

Windows Print Spooler Elevation of Privilege
Vulnerability
Important
7.8
No
No
EoP

Windows Print Spooler Elevation of Privilege
Vulnerability
Important
7.8
No
No
EoP

Windows Print Spooler Elevation of Privilege
Vulnerability
Important
7.8
No
No
EoP

Windows Print Spooler Elevation of Privilege
Vulnerability
Important
7.8
No
No
EoP

Windows Print Spooler Elevation of Privilege
Vulnerability
Important
7.8
No
No
EoP

Windows Print Spooler Elevation of Privilege
Vulnerability
Important
7.8
No
No
EoP

Windows Telephony Server Elevation of
Privilege Vulnerability
Important
7.8
No
No
EoP

Windows Win32k Elevation of Privilege
Vulnerability
Important
7.8
No
No
EoP

Windows Work Folder Service Elevation of
Privilege Vulnerability
Important
7
No
No
EoP

Microsoft Edge (Chromium-based) Elevation of
Privilege Vulnerability
Moderate
8.3
No
No
EoP

Chromium: Inappropriate implementation in
Full Screen Mode
High
N/A
No
No
RCE

Chromium: Insufficient validation of
untrusted input in WebOTP
High
N/A
No
No
RCE

Chromium: Type Confusion in V8
High
N/A
No
No
RCE

Chromium: Use after free in Portals
High
N/A
No
No
RCE

Chromium: Use after free in WebRTC
High
N/A
No
No
RCE

Chromium: Inappropriate implementation in
Background Fetch API
Medium
N/A
No
No
N/A

Chromium: Inappropriate implementation in
Web Cursor
Medium
N/A
No
No
N/A

Chromium: Use after free in Shopping Cart
Medium
N/A
No
No
RCE

Chromium: Inappropriate implementation in
Resource Timing
Low
N/A
No
No
EoP







* Indicates this CVE had previously been released by a 3rd-party and is now being incorporated into Microsoft products.

We should also call attention by some the other printer-related patches. And when it comes to large groups of patches, there are a mountain of CVEs affecting the Edge (Chromium-based) browser as well. Most of these bugs were patched by Google and consumed by Edge earlier this month. However, this demonstrates the risk of everyone relying on the same browser platform. A bug in one is now shared by many.  

In total, there are 47 patches to correct RCE bugs in this month’s patch. Beyond those already mentioned, there’s yet another RDP client bug that would allow code execution if a user connected to a malicious RDP server. If that sounds familiar, there was a similar bug last month (and more going back months prior). There are a few open-and-own bug in Office components, most notably Excel. The chances of people applying patches to Excel before April 15 seem low, so let’s hope these bugs don’t get exploited. There are a couple of intriguing bugs affecting Win32 file enumeration, although these also require a user to connect to a malicious server or share. There hasn’t been much research on this component, so it will be interesting to see if further bugs are found. Finally, there’s an RCE in Kerberos, but to be affected, the system needs Restricted Admin or Windows Defender Remote Credential Guard enabled on a box with Remote Desktop Connections configured. It’s not clear how common this configuration is, but you should check your systems and apply the update as needed.

The April release includes 59 patches to address Elevation of Privilege (EoP) bugs this month. For the most part, these are in Windows components and would need to be paired with an RCE to allow an attacker to take over a system. A few do stand out. The first is a vulnerability in the Windows Telephony Server that was reported by ZDI vulnerability researcher Simon Zuckerbraun. This flaw exists within the CreateObjectHandler COM object. Crafted method invocations on this object can trigger the deserialization of untrusted data. There are also a pair of bugs in Azure Site Recovery that should be called out as well. Don’t let the admin credential requirement fool you. This bug applies to the VMWare-to-Azure scenario, and administrators will need to upgrade to the latest version to mitigate these vulns.

There are 10 fixes address that address information disclosure bugs. For the most part, these only result in leaks consisting of unspecified memory contents. The lone exception is the bug impacting the Skype for Business. This vulnerability could inadvertently disclose file content to an attacker, but Microsoft doesn’t specific if any file content can be exposed or if just files in specific locations.

April brings eight updates to address DoS bugs, and a few stand out over the others. There’s a DoS in Microsoft Defender, but Microsoft provides no details. Another is a DoS bug in Hyper-V, which is always inconvenient if you happen to be one of the other guest OSes on that Hyper-V server. There are a trio of DoS vulnerabilities in the Windows Cluster Shared Volume (CSV) component, but again, Microsoft provides not details on how the DoS manifests. There are also no details provided about the DoS in Windows Secure Channel, but considering how much relies on .

Looking Ahead

The next Patch Tuesday falls on May 10, and we’ll return with details and patch analysis then. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!

Vollständiges Original-Advisory
Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf thezdi.com.
↗ Original-Artikel auf thezdi.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Microsoft Office Ohne Abonnement? Jetzt kostet es ein paar Hundert - Jablíčkář
1 Quelle
Windows Defender: Falsche Warnung täuscht Sicherheitslücke vor - ad-hoc-news.de
1 Quelle
DFN-CERT-2026-4930 FFmpeg: Mehrere Schwachstellen ermöglichen u. a. das Ausführen ...
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten The April 2022 Security Update Review

Thematisch verwandte Begriffe: April, 2022, Security, Update · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...