Microsoft released December 2022 patches addressing multiple vulnerabilities including…
Microsoft released December 2022 patches addressing multiple vulnerabilities including CVE-2022-44698, which is actively exploited in the wild.
On December 14, 2022, Microsoft released security updates addressing multiple vulnerabilities in Microsoft products. The Japan Information-technology Promotion Agency (IPA) issued an advisory urging immediate patching. Exploitation of these vulnerabilities could result in application crashes or allow attackers to gain control of affected systems, leading to various forms of compromise.
Microsoft confirmed active exploitation of CVE-2022-44698, indicating threat actors are already leveraging this vulnerability in real-world attacks. Given the confirmed exploitation and potential for widespread impact, IPA emphasizes the urgency of applying the available patches.
Organizations using Microsoft products should prioritize deployment of the December 2022 security updates through Windows Update or other enterprise patch management solutions. The advisory targets Japanese organizations but the underlying vulnerabilities affect Microsoft products globally.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/1214-ms.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free