Skip to main content

Microsoft Releases November 2022 Security Update

Scheduled updates for Microsoft products

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Scheduled updates for Microsoft products


The following platforms are also known to be affected:

  • .NET Framework
  • AMD CPU Branch
  • Azure Real Time Operating System
  • Linux Kernel
  • Microsoft Dynamics
  • Microsoft Graphics Component
  • Microsoft Office Excel
  • Network Policy Server (NPS)
  • Open Source Software
  • Role: Windows Hyper-V
  • SysInternals
  • Visual Studio
  • Windows Advanced Local Procedure Call
  • Windows ALPC
  • Windows Bind Filter Driver
  • Windows BitLocker
  • Windows CNG Key Isolation Service
  • Windows Devices Human Interface
  • Windows Digital Media
  • Windows DWM Core Library
  • Windows Extensible File Allocation
  • Windows Group Policy Preference Client
  • Windows HTTP.sys
  • Windows Kerberos
  • Windows Mark of the Web (MOTW)
  • Windows Netlogon
  • Windows Network Address Translation (NAT)
  • Windows ODBC Driver
  • Windows Overlay Filter
  • Windows Point-to-Point Tunneling Protocol
  • Windows Print Spooler Components
  • Windows Resilient File System (ReFS)
  • Windows Scripting
  • Windows Win32K

Threat details

Introduction

Microsoft has released updates to address 68 vulnerabilities in Microsoft products, with 11 of them rated as Critical. An unauthenticated, remote attacker could exploit some of these vulnerabilities to allow privilege escalation, spoofing, denial-of-service, or remote code execution to take control of an affected system.

Exploitation in the wild

Microsoft have reported active exploitation of six vulnerabilities, with one being publicly disclosed. In addition to this cyber alert, NHS Digital has a released high severity cyber alert CC-4210 and requires affected organisations to read Microsoft guidance for CVE-2022-41040, CVE-2022-41082 and the November 2022 Exchange Server Security Updates Exchange Team blog post.

Microsoft has also confirmed active exploitation of CVE-2022-41080 and strongly recommends prioritising deployment of the relevant patch for this vulnerability to reduce impact.


Threat updates

Date Update
19 Dec 2022 Microsoft confirms active exploitation of CVE-2022-41080

Microsoft confirms active exploitation of CVE-2022-41080 and strongly recommends prioritising deployment of KB5019758 patch to reduce impact. This article has been updated to reflect this information. 

18 Nov 2022 OOB update to address an issue with sign in and Kerberos authentication

Microsoft is releasing Out-of-band (OOB) security updates for installation on all the Domain Controllers (DCs) in affected environments. This update addresses a known issue which might cause sign in failures or other Kerberos authentication issues. You do not need to install any update or make any changes to other servers or client devices in your environment to resolve this issue. If you used any workaround or mitigations for this issue, they are no longer needed, and we recommend you remove them.

Please refer to the Microsoft Release Health Blog for more information regarding where to find a relevant update.


Remediation advice

Affected organisations are encouraged to review Microsoft’s November 2022 Security Update Summary and Deployment Information and apply the relevant updates.



Last edited: 19 December 2022 12:25 pm