VORANT. Threat Intelligence Sign in Get the full feed

Microsoft released December 2022 patches addressing multiple vulnerabilities including…

high vulnerability

Microsoft released December 2022 patches addressing multiple vulnerabilities including CVE-2022-44698, which is actively exploited in the wild.

On December 14, 2022, Microsoft released security updates addressing multiple vulnerabilities in Microsoft products. The Japan Information-technology Promotion Agency (IPA) issued an advisory urging immediate patching. Exploitation of these vulnerabilities could result in application crashes or allow attackers to gain control of affected systems, leading to various forms of compromise.

Microsoft confirmed active exploitation of CVE-2022-44698, indicating threat actors are already leveraging this vulnerability in real-world attacks. Given the confirmed exploitation and potential for widespread impact, IPA emphasizes the urgency of applying the available patches.

Organizations using Microsoft products should prioritize deployment of the December 2022 security updates through Windows Update or other enterprise patch management solutions. The advisory targets Japanese organizations but the underlying vulnerabilities affect Microsoft products globally.

Mentioned in this report

Vulnerabilities CVE-2022-44698KEV

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/1214-ms.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free