# Microsoft released December 2022 patches addressing multiple vulnerabilities including…

Published: 2022-12-13 · Severity: high
Canonical: https://vorant.io/reports/a902373b-46ac-4926-965f-1842db48e53b/microsoft-released-december-2022-patches-addressing-multiple-vulnerabilities

> Microsoft released December 2022 patches addressing multiple vulnerabilities including CVE-2022-44698, which is actively exploited in the wild.

On December 14, 2022, Microsoft released security updates addressing multiple vulnerabilities in Microsoft products. The Japan Information-technology Promotion Agency (IPA) issued an advisory urging immediate patching. Exploitation of these vulnerabilities could result in application crashes or allow attackers to gain control of affected systems, leading to various forms of compromise.

Microsoft confirmed active exploitation of CVE-2022-44698, indicating threat actors are already leveraging this vulnerability in real-world attacks. Given the confirmed exploitation and potential for widespread impact, IPA emphasizes the urgency of applying the available patches.

Organizations using Microsoft products should prioritize deployment of the December 2022 security updates through Windows Update or other enterprise patch management solutions. The advisory targets Japanese organizations but the underlying vulnerabilities affect Microsoft products globally.

## Mentioned in this report

- Vulnerabilities: CVE-2022-44698 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/1214-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a902373b-46ac-4926-965f-1842db48e53b/microsoft-released-december-2022-patches-addressing-multiple-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
