CVE-2022-22047
published 2022-07-12CVE-2022-22047: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
PriorityP182high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-08-02
Exploited in the wild
EPSS
18.77%
97.0th percentile
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19360 | 10.0.10240.19360 |
| microsoft | windows_10_1607 | < 10.0.14393.5246 | 10.0.14393.5246 |
| microsoft | windows_10_1809 | < 10.0.17763.3165 | 10.0.17763.3165 |
| microsoft | windows_10_20h2 | < 10.0.19042.1826 | 10.0.19042.1826 |
| microsoft | windows_10_21h1 | < 10.0.19043.1826 | 10.0.19043.1826 |
| microsoft | windows_10_21h2 | < 10.0.19044.1826 | 10.0.19044.1826 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19360 | 10.0.10240.19360 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5246 | 10.0.14393.5246 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3165 | 10.0.17763.3165 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3165 | 10.0.17763.3165 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1826 | 10.0.19042.1826 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1826 | 10.0.19043.1826 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.1826 | 10.0.19044.1826 |
| microsoft | windows_11_21h2 | < 10.0.22000.795 | 10.0.22000.795 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.795 | 10.0.22000.795 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.26022 | 6.1.7601.26022 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.26022 | 6.1.7601.26022 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20478 | 6.3.9600.20478 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.26022 | 6.1.7601.26022 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.21569 | 6.0.6003.21569 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23771 | 6.2.9200.23771 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20478 | 6.3.9600.20478 |
| microsoft | windows_server_2016 | < 10.0.14393.5246 | 10.0.14393.5246 |
Detection & IOCsextracted from sources · hover to see the quote
- →Talos has published multiple Snort rules to detect exploitation attempts of CVE-2022-22047; consult the Talos Patch Tuesday blog post for the specific rule IDs. ↗
- →Successful exploitation results in code execution as SYSTEM; hunt for unexpected SYSTEM-level process creation originating from CSRSS (csrss.exe) child processes. ↗
- →CVE-2022-22047 was weaponised by threat actor KNOTWEED (Denim Tsunami) to deploy the Subzero malware; detections for win.subzero should be prioritised alongside this CVE. ↗
- →Check Point IPS signature 'Microsoft Windows Client/Server Runtime Subsystem Elevation of Privilege (CVE-2022-22047)' can be used as a detection reference for network-level coverage. ↗
- →Microsoft confirmed active in-the-wild exploitation at time of patch release; treat any unpatched CSRSS process anomalies as high-priority incidents. ↗
- ·Exploitation requires local/physical access to the target machine; remote-only detection approaches will not cover the full attack surface. ↗
- ·The Talos Snort rule IDs for CVE-2022-22047 are not enumerated in the newsletter; analysts must retrieve them from the linked Patch Tuesday blog post. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mqc2-2jgq-8887: Windows CSRSS Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-07-13·CVSS 7.8
CVE-2022-22026 [HIGH] CWE-269 GHSA-mqc2-2jgq-8887: Windows CSRSS Elevation of Privilege Vulnerability
Windows CSRSS Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-22047, CVE-2022-22049.
GHSA
GHSA-p4j8-4hv2-8733: Windows CSRSS Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-07-13·CVSS 8.8
CVE-2022-22047 [HIGH] CWE-269 GHSA-p4j8-4hv2-8733: Windows CSRSS Elevation of Privilege Vulnerability
Windows CSRSS Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-22026, CVE-2022-22049.
GHSA
GHSA-8gv9-w486-3g6c: Windows CSRSS Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-07-13·CVSS 8.8
CVE-2022-22049 [HIGH] CWE-787 GHSA-8gv9-w486-3g6c: Windows CSRSS Elevation of Privilege Vulnerability
Windows CSRSS Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-22026, CVE-2022-22047.
VulnCheck
Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability
vulncheck·2022·CVSS 7.8
CVE-2022-22047 [HIGH] CWE-426 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability
Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability
Microsoft Windows CSRSS contains an unspecified vulnerability that allows for privilege escalation to SYSTEM privileges.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2022-Jul; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.microsoft.com/en-us/security/blog/2022/07/27/untangling-knotweed-european-private-sector-offensive-actor-using-0-day-exploits/; https://decoded.avast.io/threatresearch/avast-q3-2022-threat-report/; https://raw.githubusercontent.co
Project0
Project Zero RCA: CVE-2022-41073: Windows Activation Contexts EoP
project_zero·CVSS 7.8
CVE-2022-41073 [HIGH] Project Zero RCA: CVE-2022-41073: Windows Activation Contexts EoP
# CVE-2022-41073: Windows Activation Contexts EoP
*Maddie Stone & James Forshaw*
## The Basics
**Disclosure or Patch Date:** November 08, 2022
**Product:** Windows
**Advisory:** https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41073
**Affected Versions:** pre-KB5019980 (Win 11), pre-KB5019959 (Win 10)
**First Patched Version:** KB5019980 (Win 11), KB5019959 (Win 10)
**Issue/Bug Report:** N/A
**Patch CL:** N/A
**Bug-Introducing CL:** N/A
**Reporter(s):** Microsoft Threat Intelligence Center (MSTIC)
## The Code
**Proof-of-concept:** See exploit sample
**Exploit sample:** https://www.virustotal.com/gui/file/e8a94466e64fb5f84eea5d8d1ba64054a61abf66fdf85ac160a95b204b7b19f3/details
**Did you have access to the exploit sample when doing the analysis?** Yes
## The Vuln
Microsoft
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
vendor_msrc·2022-07-12·CVSS 7.8
CVE-2022-22047 [HIGH] Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Client/Server Runtime Subsystem: Windows Client/Server Runtime Subsystem
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:Yes;Latest Software Release:Exploitation Detected;Older Software Release:Exploitation Detected;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5015811
Reference: https://support.microsoft.com/help/5015811
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=
CISA
Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability
cisa·2022-07-12·CVSS 7.8
CVE-2022-22047 [HIGH] CWE-426 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability
Affected: Microsoft Windows
Microsoft Windows CSRSS contains an unspecified vulnerability that allows for privilege escalation to SYSTEM privileges.
Required Action: Apply updates per vendor instructions.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22047; https://nvd.nist.gov/vuln/detail/CVE-2022-22047
Remediation Due Date: 2022-08-02
No detection rules found.
No public exploits indexed.
Securelist
A patched Windows attack surface is still exploitable
blogs_securelist·2024-03-14·CVSS 7.8
CVE-2022-22047 [HIGH] A patched Windows attack surface is still exploitable
Table of Contents
CSRSS | CVE-2022-22047
CSRSS | CVE-2022-37989
Print Spooler | CVE-2022-29104
Print Spooler | CVE-2022-41073
Windows Error Reporting | CVE-2023-36874
File History Service | CVE-2023-35359
Windows Error Reporting – 2nd exploit | CVE-2023-35359
BITS | CVE-2023-35359
How was the patch for this attack surface applied?
How to check if a vulnerability was exploited or any attempts were made to exploit it?
Authors
Elsayed Elrefaei
Ashraf Refaat
Kaspersky GERT
On August 8, 2023, Microsoft finally released a kernel patch for a class of vulnerabilities affecting Microsoft Windows since 2015 . The vulnerabilities lead to elevation of privilege (EoP), which allows an account with user rights to gain SYSTEM privileges on a vulnerable host. The root cause of this attack s
Securelist
A patched Windows attack surface is still exploitable
blogs_securelist·2024-03-14·CVSS 7.8
CVE-2022-22047 [HIGH] A patched Windows attack surface is still exploitable
Table of Contents
- CSRSS | CVE-2022-22047
- CSRSS | CVE-2022-37989
- Print Spooler | CVE-2022-29104
- Print Spooler | CVE-2022-41073
- Windows Error Reporting | CVE-2023-36874
- File History Service | CVE-2023-35359
- Windows Error Reporting – 2nd exploit | CVE-2023-35359
- BITS | CVE-2023-35359
- How was the patch for this attack surface applied?
- How to check if a vulnerability was exploited or any attempts were made to exploit it?
Authors
- Elsayed Elrefaei
- Ashraf Refaat
- Kaspersky GERT
On August 8, 2023, Microsoft finally released a kernel patch for a class of vulnerabilities affecting Microsoft Windows since 2015. The vulnerabilities lead to elevation of privilege (EoP), which allows an account with user rights to gain SYSTEM privileges on a vulnerable host. The root cause o
Tenable
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
blogs_tenable·2023-08-03
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
IT threat evolution in Q3 2022. Non-mobile statistics
blogs_securelist·2022-11-18
IT threat evolution in Q3 2022. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Number of users attacked by banking malware
TOP 10 banking malware families
Geography of financial malware attacks
Ransomware programs
Quarterly trends and highlights
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by criminals during cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
TOP 20 threats for macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
Countries and territories that serve as sources of web-ba
Securelist
PC malware statistics, Q3 2022
blogs_securelist·2022-11-18
PC malware statistics, Q3 2022
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by criminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q3 2022
- IT threat evolution in Q3 2022. Non-mobile statistics
- IT threat evolution in Q3 2022. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q3 2022:
- Kaspersky solutions blocked 956,074,958 attacks from online resources across the globe.
- Web Anti-Virus recognized 251,288,987 unique URLs as malicious.
- Attempts to run malware fo
Qualys
Introducing Qualys Threat Research Thursdays
blogs_qualys·2022-09-01
Introducing Qualys Threat Research Thursdays
## Table of Contents
Threat Intelligence from the Qualys Blog
New Threat Hunting Tools & Techniques
New Vulnerabilities
Introducing the Monthly Threat Thursdays Webinar
Welcome to the first edition of the Qualys Research Team’s “Threat Research Thursday” where we collect and curate notable new tools, techniques, procedures, threat intelligence, cybersecurity news, malware attacks, and more. We will endeavor to issue these update reports regularly, as often as every other week, or as our threat intelligence output warrants.
## Threat Intelligence from the Qualys Blog
Here is a roundup of the most interesting blogs from the Qualys Research Team from the past couple of weeks:
New Qualys Research Report: Evolution of Quasar RAT – This free downloadable report gives a sneak peek of the
Qualys
Introducing Qualys Threat Research Thursdays | Qualys
blogs_qualys·2022-09-01
Introducing Qualys Threat Research Thursdays | Qualys
#### Table of Contents
- Threat Intelligence from the Qualys Blog
- New Threat Hunting Tools & Techniques
- New Vulnerabilities
- Introducing the Monthly Threat Thursdays Webinar
Welcome to the first edition of the Qualys Research Team’s “Threat Research Thursday” where we collect and curate notable new tools, techniques, procedures, threat intelligence, cybersecurity news, malware attacks, and more. We will endeavor to issue these update reports regularly, as often as every other week, or as our threat intelligence output warrants.
## Threat Intelligence from the Qualys Blog
Here is a roundup of the most interesting blogs from the Qualys Research Team from the past couple of weeks:
- New Qualys Research Report: Evolution of Quasar RAT – This free downloadable report gives a sneak pee
Checkpoint
1st August – Threat Intelligence Report
blogs_checkpoint·2022-08-01·CVSS 7.8
CVE-2022-22047 [HIGH] 1st August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 1st August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 1st August, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The LockBit Ransomware gang has claimed the attack on Italy’s tax agency, the Internal Revenue Service. According to LockBit’s message on their dark web site, the group stole 100 GB of sensitive data, including financial reports, contracts and other documents that they threaten to leak online if the victim does not pay the ra
Talos
Threat Source newsletter (July 21, 2022) — No topic is safe from being targeted by fake news and disinformation
blogs_talos·2022-07-21
Threat Source newsletter (July 21, 2022) — No topic is safe from being targeted by fake news and disinformation
Welcome to this week’s edition of the Threat Source newsletter.
I could spend time in this newsletter every week talking about fake news. There are always so many ridiculous memes, headlines, misleading stories, viral Facebook posts and manipulated media that I see come across my Instagram feed or via my wife when she shows me TikToks she favorited.
One recent event, though, was so crushing to me that I had to call it out specifically. Former Japanese Prime Minister Shinzo Abe was assassinated earlier this month while making a campaign speech in public. This was a horrible tragedy marking the death of a powerful politician in one of the world’s most influential countries. It was the top story in the world for several days and was even more shocking given Japan’s strict gun laws and the r
Talos
Threat Source newsletter (July 21, 2022) — No topic is safe from being targeted by fake news and disinformation
blogs_talos·2022-07-21
Threat Source newsletter (July 21, 2022) — No topic is safe from being targeted by fake news and disinformation
## Threat Source newsletter (July 21, 2022) — No topic is safe from being targeted by fake news and disinformation
Welcome to this week’s edition of the Threat Source newsletter.
I could spend time in this newsletter every week talking about fake news. There are always so many ridiculous memes, headlines, misleading stories, viral Facebook posts and manipulated media that I see come across my Instagram feed or via my wife when she shows me TikToks she favorited.
One recent event, though, was so crushing to me that I had to call it out specifically. Former Japanese Prime Minister Shinzo Abe was assassinated earlier this month while making a campaign speech in public. This was a horrible tragedy marking the death of a powerful politician in one of the world’s most influential countries. I
Checkpoint
18th July – Threat Intelligence Report
blogs_checkpoint·2022-07-18
CVE-2022-2033 18th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 18th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 18th July, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
A callback phishing campaign has been observed targeting corporate networks while impersonating known cybersecurity companies – the emails mention an alleged threat in the target’s network, asking them to call the company and let them in the network to investigate. Some suggest the operation is done by the Quantum ransomware ga
Krebs
Microsoft Patch Tuesday, July 2022 Edition
blogs_krebs·2022-07-13·CVSS 7.8
[HIGH] Microsoft Patch Tuesday, July 2022 Edition
Microsoft today released updates to fix at least 86 security vulnerabilities in its Windows operating systems and other software, including a weakness in all supported versions of Windows that Microsoft warns is actively being exploited. The software giant also has made a controversial decision to put the brakes on a plan to block macros in Office documents downloaded from the Internet.
In February, security experts hailed Microsoft’s decision to block VBA macros in all documents downloaded from the Internet. The company said it would roll out the changes in stages between April and June 2022.
Macros have long been a trusted way for cybercrooks to trick people into running malicious code. Microsoft Office by default warns users that enabling macros in untrusted documents is a security ri
Talos
Microsoft Patch Tuesday for July 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-07-12·CVSS 8.1
[HIGH] Microsoft Patch Tuesday for July 2022 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for July 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing more than 80 vulnerabilities in the company’s various software, hardware and firmware offerings, including one that’s actively being exploited in the wild.
July's security update features three critical vulnerabilities, up from one last month, still lower than Microsoft’s average in a Patch Tuesday. All the other vulnerabilities fixed are considered “important.”
All three critical vulnerabilities allow remote code execution on Microsoft Windows Systems. Of these, Microsoft considers the exploitation of CVE-2022-22029 , CVE-2022-22038 and CVE-2022-22039 less likely to occur. CVE-2022-22029 could be exploited over the network by making an
Talos
Microsoft Patch Tuesday for July 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-07-12·CVSS 8.1
[HIGH] Microsoft Patch Tuesday for July 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing more than 80 vulnerabilities in the company’s various software, hardware and firmware offerings, including one that’s actively being exploited in the wild.
July's security update features three critical vulnerabilities, up from one last month, still lower than Microsoft’s average in a Patch Tuesday. All the other vulnerabilities fixed are considered “important.”
All three critical vulnerabilities allow remote code execution on Microsoft Windows Systems. Of these, Microsoft considers the exploitation of CVE-2022-22029, CVE-2022-22038 and CVE-2022-22039 less likely to occur. CVE-2022-22029 could be exploited over the network by making an unauthenticated, specially crafted call to a Network File System (NFS). However, accord
Krebs
Microsoft Patch Tuesday, July 2022 Edition
blogs_krebs·2022-07-12·CVSS 7.8
[HIGH] Microsoft Patch Tuesday, July 2022 Edition
Microsoft today released updates to fix at least 86 security vulnerabilities in its Windows operating systems and other software, including a weakness in all supported versions of Windows that Microsoft warns is actively being exploited. The software giant also has made a controversial decision to put the brakes on a plan to block macros in Office documents downloaded from the Internet.
In February, security experts hailed Microsoft’s decision to block VBA macros in all documents downloaded from the Internet. The company said it would roll out the changes in stages between April and June 2022.
Macros have long been a trusted way for cybercrooks to trick people into running malicious code. Microsoft Office by default warns users that enabling macros in untrusted documents is a security ri
Qualys
July 2022 Patch Tuesday | Microsoft Releases 84 Vulnerabilities with 4 Critical, plus 2 Microsoft Edge (Chromium-Based) | Qualys
blogs_qualys·2022-07-12·CVSS 7.8
[HIGH] July 2022 Patch Tuesday | Microsoft Releases 84 Vulnerabilities with 4 Critical, plus 2 Microsoft Edge (Chromium-Based) | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- The July 2022 Microsoft Vulnerabilities Are Classified As Follows:
- Notable Microsoft Vulnerabilities Patched
- Microsoft Critical Vulnerability Highlights
- Microsoft Last But Not Least
- Adobe Security Bulletins and Advisories
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response With Patch Management (PM)
- Qualys Monthly Webinar Series
- Join the Webinar This Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 84 vulnerabilities (aka flaws) in the July 2022 update, including four vulnerabilities classified as critical as they allow Remote Code Execution (RCE). This month’s Patch Tuesday cumulative Windows update includes the fix
Qualys
July 2022 Patch Tuesday | Microsoft Releases 84 Vulnerabilities With 4 Critical, Plus 2 Microsoft Edge (Chromium-Based); Adobe Releases 4 Advisories, 27 Vulnerabilities With 18 Critical.
blogs_qualys·2022-07-12·CVSS 7.8
[HIGH] July 2022 Patch Tuesday | Microsoft Releases 84 Vulnerabilities With 4 Critical, Plus 2 Microsoft Edge (Chromium-Based); Adobe Releases 4 Advisories, 27 Vulnerabilities With 18 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
The July 2022 Microsoft Vulnerabilities Are Classified As Follows:
Notable Microsoft Vulnerabilities Patched
Microsoft Critical Vulnerability Highlights
Microsoft Last But Not Least
Adobe Security Bulletins and Advisories
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response With Patch Management (PM)
Qualys Monthly Webinar Series
Join the Webinar This Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 84 vulnerabilities (aka flaws) in the July 2022 update, including four vulnerabilities classified as critical as they allow Remote Code Execution (RCE). This month’s Patch Tuesday cumulative Windows update includes the fix for one acti
Tenable
Microsoft’s July 2022 Patch Tuesday Addresses 84 CVEs (CVE-2022-22047)
blogs_tenable·2022-07-12·CVSS 7.8
[HIGH] Microsoft’s July 2022 Patch Tuesday Addresses 84 CVEs (CVE-2022-22047)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Crowdstrike
July Patch Tuesday 2022: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] July Patch Tuesday 2022: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Threat Intel
Denim Tsunami
threat_intel·CVSS 7.8
CVE-2022-22047 [HIGH] Denim Tsunami
# Threat Actor: Denim Tsunami
## Description
Denim Tsunami is a threat actor group that has been involved in targeted attacks against European and Central American customers. They have been observed using multiple Windows and Adobe 0-day exploits, including one for CVE-2022-22047, which is a privilege escalation vulnerability. Denim Tsunami developed a custom malware called Subzero, which has capabilities such as keylogging, capturing screenshots, data exfiltration, and running remote shells. They have also been associated with the Austrian spyware distributor DSIRF.
## Associated Malware Families (1)
win.subzero
Crowdstrike
July Patch Tuesday 2022: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] July Patch Tuesday 2022: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Zscaler
Zscaler found Windows security vulnerabilities | 07-12-2022
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler found Windows security vulnerabilities | 07-12-2022
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
2022-07-12
Published
2022-07-12
Added to CISA KEV
Exploited in the wild