• Tech News
    • Games
    • Pc & Laptop
    • Mobile Tech
    • Ar & Vr
    • Security
  • Startup
    • Fintech
  • Reviews
  • How To
What's Hot

Elementor #32036

January 24, 2025

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

April 18, 2024

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

April 16, 2024
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
    1. Games
    2. Pc & Laptop
    3. Mobile Tech
    4. Ar & Vr
    5. Security
    6. View All

    Bring Elden Ring to the table with the upcoming board game adaptation

    September 19, 2022

    ONI: Road to be the Mightiest Oni reveals its opening movie

    September 19, 2022

    GTA 6 images and footage allegedly leak

    September 19, 2022

    Wild west adventure Card Cowboy turns cards into weird and silly stories

    September 18, 2022

    7 Reasons Why You Should Study PHP Programming Language

    October 19, 2022

    Logitech MX Master 3S and MX Keys Combo for Business Gen 2 Review

    October 9, 2022

    Lenovo ThinkPad X1 Carbon Gen10 Review

    September 18, 2022

    Lenovo IdeaPad 5i Chromebook, 16-inch+120Hz

    September 3, 2022

    It’s 2023 and Spotify Still Can’t Say When AirPlay 2 Support Will Arrive

    April 4, 2023

    YouTube adds very convenient iPhone homescreen widgets

    October 15, 2022

    Google finishes iOS 16 Lock Screen widgets rollout w/ Maps

    October 14, 2022

    Is Apple actually turning iMessage into AIM or is this sketchy redesign rumor for laughs?

    October 14, 2022

    MeetKai launches AI-powered metaverse, starting with a billboard in Times Square

    August 10, 2022

    The DeanBeat: RP1 simulates putting 4,000 people together in a single metaverse plaza

    August 10, 2022

    Improving the customer experience with virtual and augmented reality

    August 10, 2022

    Why the metaverse won’t fall to Clubhouse’s fate

    August 10, 2022

    How Apple privacy changes have forced social media marketing to evolve

    October 16, 2022

    Microsoft Patch Tuesday October Fixed 85 Vulnerabilities – Latest Hacking News

    October 16, 2022

    Decentralization and KYC compliance: Critical concepts in sovereign policy

    October 15, 2022

    What Thoma Bravo’s latest acquisition reveals about identity management

    October 14, 2022

    What is a Service Robot? The vision of an intelligent service application is possible.

    November 7, 2022

    Tom Brady just chucked another Microsoft Surface tablet

    September 18, 2022

    The best AIO coolers for your PC in 2022

    September 18, 2022

    YC’s Michael Seibel clarifies some misconceptions about the accelerator • DailyTech

    September 18, 2022
  • Startup
    • Fintech
  • Reviews
  • How To
Behind The ScreenBehind The Screen
Home»Tech News»August ’22 a bumper month for high-impact vulnerabilities
Tech News

August ’22 a bumper month for high-impact vulnerabilities

September 10, 2022No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
August ’22 a bumper month for high-impact vulnerabilities
Share
Facebook Twitter LinkedIn Pinterest Email

The disclosure of multiple impactful and, critically, widespread vulnerabilities and proof-of-concept (POC) exploits made August a busy month for patching, with urgent updates needed for users of Apple and Google products, while corporate security teams were kept on their toes with fixes for vulns targeting Microsoft, Palo Alto and VMware, among others.

That is according to the third edition of Recorded Future’s CVE monthly report, in which the firm’s analysts highlighted some of the most critical bugs, including CVE-2022-2856 in Google’s Chrome web browser, and CVE-2022-32893 and -32894 in Apple Safari WebKit, Apple iOS, iPadOS and macOS, all of which are particularly important in part because of their vast user bases.

“When it rains, it pours,” said the analyst team. “As if the landscape was not content to simply break the dry spell of June, the number of high-risk vulnerabilities that we identified for August 2022 was over double the number from July, driven by two categories: disclosures of several zero-day vulnerabilities in products from major vendors like Apple, Google, and Microsoft; and releases of POC exploits for critical vulnerabilities in software from both our prioritised vendors and a diverse group of others.

“Unlike last month, there was a nearly equal distribution of high-risk vulnerabilities between our prioritised vendors and others. For our prioritised list, OSs and web browsers were principally affected. Outside of this list, we saw a wide spread of affected components, including router firmware, device management, interface controllers and learning management software.

“As is to be expected based on trends from the last several years, all of the high-risk vulnerabilities for this past month with CVSS scores were of low attack complexity. However, POC exploit code for these vulnerabilities ranged from a few lines to multi-file packages.”

See also  Valheim coming to PC Game Pass at the end of this month

The full list of prioritised vulnerabilities – in order of potential severity – is as follows:

  • CVE-2022-2856 in Google’s Chrome web browser.
  • CVE-2022-27255 in Realtek’s eCos interface controller.
  • CVE-2022-32548 in DrayTek’s Vigor router firmware.
  • CVE-2022-32893 in Apple’s Safari Webkit web browser.
  • CVE-2022-32894 in Apple’s iOS, iPadOS, and macOS operating system.
  • CVE-2022-34699 in Microsoft’s Windows and Windows Server operating system.
  • CVE-2022-31656 in VMWare’s Workspace ONE Access, Identity Manager, and vRealize Automation device management.
  • CVE-2022-31659 in VMWare’s Workspace ONE Access and Identity Manager device management.
  • CVE-2022-0028 in Palo Alto Networks’s PAN-OS operating system.
  • CVE-2022-34713 in Microsoft Windows and Windows Server operating system.
  • CVE-2020-14321 in Moodle’s learning management system.

Of these, some of the more noteworthy issues included CVE-2022-34713, also known as DogWalk, which is disputed as a zero-day because technically, exploitation was reported after its initial disclosure, which occurred in 2020. The Recorded Future team said its exploitation confirmed their suspicions that non-macro-related Microsoft vulnerabilities that are exploitable via malicious documents would become a trending feature of the threat landscape.

The VMware vulnerabilities – which are not zero-days either – were disclosed as a pair on 2 August, CVE-2022-31656 being an authentication bypass vulnerability and CVE-2022-31659 being an SQL injection vulnerability. POC code was spotted in the wild a few days later on 9 August.

VMware users have been highly targeted by nation state advanced persistent threat (APT) groups and cyber criminal gangs throughout 2022 – its Horizon platform in particular became the subject of an alert from the US authorities in June. Prior to the August disclosures, VMware alerted users in April to CVE-2022-22954, a server-side template injection bug leading to remote code execution (RCE), which is thought to have been exploited by Iran-linked threat actors.

See also  iPhone 14 buyers will have a day-one patch to download

Recorded Future has been producing a monthly CVE bulletin since June 2022 – launched to coincide with the debut of Microsoft’s Windows Autopatch service, which has forever changed the nature of Patch Tuesday for security pros at thousands of large enterprises.

Source link

August bumper highimpact month vulnerabilities
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

How a 32-Year-Old Couple Makes $100K Per Month In Semi-Passive Income

June 2, 2023

What is a Service Robot? The vision of an intelligent service application is possible.

November 7, 2022

Microsoft Patch Tuesday October Fixed 85 Vulnerabilities – Latest Hacking News

October 16, 2022

Vulnerabilities Found In Canon Medical Vitrea View Software

October 3, 2022
Add A Comment

Comments are closed.

Editors Picks

Dutchie fixes the all-cash conundrum at authorized dispensaries

July 22, 2022

VG247’s The Best Games Ever Podcast – Ep.5: Best game you got for an odd reason

June 27, 2022

Elizabeth Holmes of Theranos Gets 11 Years in Prison

November 19, 2022

Asian gothic ARPG Black Witchcraft gets delayed after recently revealing release date

September 3, 2022

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Elementor #32036

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2025 behindthescreen.uk - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.