• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

My TechDecisions

  • Best of Tech Decisions
  • Topics
    • Video
    • Audio
    • Mobility
    • Unified Communications
    • IT Infrastructure
    • Network Security
    • Physical Security
    • Facility
    • Compliance
  • RFP Resources
  • Resources
  • Podcasts
  • Project of the Week
  • About Us
    SEARCH
Compliance, IT Infrastructure, Network Security, News

April 2022 Patch Tuesday: 10 Critical Microsoft Bugs, RCEs and More

Microsoft has released patches for 128 CVEs this Patch Tuesday, including several critical bugs that admins should patch quickly.

April 12, 2022 Zachary Comeau Leave a Comment

Fortinet Vulnerability, Fortigate
stock.adobe.com

IT admins have a lot of patching to do this month as Microsoft has released patches to address nearly 130 security vulnerabilities, including 10 critical bugs and three with a CVSS of 9.8.

According to Zero Day Initiative (ZDI), the vulnerability disclosure initiative of cybersecurity firm Trend Micro, this volume of patches has not been seen since the fall of 2020, but the level is somewhat similar to the first quarter of last year.

The 128 bugs patched by Microsoft this Patch Tuesday are in addition to the 17 CVEs consumed from the Chromium Open-Source Software by Microsoft Edge, bringing the total number of April bugs to 145.

Vulnerable products include RCP Runtime Library, Windows Network File System, Microsoft Defender, Exchange Sever, Print Spooler, Windows Hyper-V, DNS Server, Skype and more.

Here’s a look at some of the more alarming vulnerabilities that admins should prioritize, as outlined by ZDI:

CVE-2022-26809 – RPC Runtime Library Remote Code Execution Vulnerability

This flaw could allow a remote attacker to execute code at high privileges on an affected system without user interaction, making the bug potentially wormable, at least between machines where RPC can be reached, according to ZDI. The static port used, TCP port 135, is usually blocked at the network perimeter, but attackers could still use it for lateral movement. With a CVSS of 9.8, this is one admins should test and deploy quickly.

CVE-2022-24491/24497 – Windows Network File System Remote Code Execution Vulnerability

Both of these bugs also get a CVSS of 9.8, and Microsoft says exploitation is more likely. According to ZDI, a remote attacker on systems where the NFS role is enabled could execute code on an affected system with high privileges without user interaction.

Those factors also lead to a potentially wormable vulnerability, at least between NFS servers. Like RPC, this is blocked at the network perimeter, but Microsoft does provide guidance on how the RPC port multiplexer (port 2049) is firewall-friendly and simplifies deployment of NFS. Roll out these patches rapidly, ZDI advises.

CVE-2022-26815 – Windows DNS Server Remote Code Execution Vulnerability

Microsoft patched 18 DNS Server bugs this month, but this is the most severe of them, with a CVSS of 8.8. ZDI notes that this particular bug is similar to one patched in February, leading to the thought that this fixes what the first patch didn’t. Per ZDI, exploitation of this bug requires dynamic updates to be enabled and some elevated privileges.

CVE-2022-26904 – Windows User Profile Service Elevation of Privilege Vulnerability

According to ZDI, this bug allows an attacker to gain code execution at SYSTEM level on affected systems, but they need some level of privileges before they could escalate. These are often paired with other bugs to completely take over a system. This is also one of the publicly known vulnerabilities patched this month, and there is also a proof-of-concept out for it and a Metasploit module as well.

CVE-2022-24521 – Windows Common Log File System Driver Elevation of Privilege Vulnerability

This is the only bug Microsoft lists as under active exploitation and was reported by the National Security Agency, so this is not to be taken lightly. It is likely paired with another RCE bug, ZDI says. It’s unclear how widespread exploitation is, but admins shouldn’t wait to find out.

Read ZDI’s blog for more information on the full list of patches, including four updates that fix 70 CVEs in Adobe products, including Acrobat and Reader, Photoshop, After Effects, and Adobe Commerce.

If you enjoyed this article and want to receive more valuable industry content like this, click here to sign up for our digital newsletters!

Tagged With: Microsoft, Patch management, Patch Tuesday

Related Content:

  • Cloud, SASE, Aryaka How the Cloud is Redefining Media Production and…
  • Singlewire Software mass notification interview Singlewire Software on Mass Notification Solutions
  • URI catchbox 1 Catchbox Plus: The Mic Solution That Finally Gave…
  • Engaging virtual meeting with diverse participants discussing creative ideas in a bright office space during daylight hours Diversified Survey: Workplace AV Tech is Falling Short,…

Free downloadable guide you may like:

  • Practical Design Guide for Office SpacesPractical Design Guide for Office Spaces

    Recent Gartner research shows that workers prefer to return to the office for in-person meetings for relevant milestones, as well as for face-to-face time with co-workers. When designing the office spaces — and meeting spaces in particular — enabling that connection between co-workers is crucial. But introducing the right collaboration technology in meeting spaces can […]

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest Downloads

Practical Design Guide for Office Spaces
Practical Design Guide for Office Spaces

Recent Gartner research shows that workers prefer to return to the office for in-person meetings for relevant milestones, as well as for face-to-fa...

New Camera Can Transform Your Live Production Workflow
New Camera System Can Transform Your Live Production Workflow

Sony's HXC-FZ90 studio camera system combines flexibility and exceptional image quality with entry-level pricing.

Creating Great User Experience and Ultimate Flexibility with Clickshare

Working and collaborating in any office environment today should be meaningful, as workers today go to office for very specific reasons. When desig...

View All Downloads

Would you like your latest project featured on TechDecisions as Project of the Week?

Apply Today!

More from Our Sister Publications

Get the latest news about AV integrators and Security installers from our sister publications:

Commercial IntegratorSecurity Sales

AV-iQ

Footer

TechDecisions

  • Home
  • Welcome to TechDecisions
  • Contact Us
  • Comment Guidelines
  • RSS Feeds
  • Twitter
  • Facebook
  • Linkedin

Free Technology Guides

FREE Downloadable resources from TechDecisions provide timely insight into the issues that IT, A/V, and Security end-users, managers, and decision makers are facing in commercial, corporate, education, institutional, and other vertical markets

View all Guides
TD Project of the Week

Get your latest project featured on TechDecisions Project of the Week. Submit your work once and it will be eligible for all upcoming weeks.

Enter Today!
Emerald Logo
ABOUTCAREERSAUTHORIZED SERVICE PROVIDERSYour Privacy ChoicesTERMS OF USEPRIVACY POLICY

© 2025 Emerald X, LLC. All rights reserved.