Skip to content ↓ | Skip to navigation ↓

Tripwire’s June 2022 Patch Priority Index (PPI) brings together important vulnerabilities for Microsoft.

First on the patch priority list this month is a patch for a remote code execution vulnerability in Edge.

Next are patches for Office and Excel that resolve 3 information disclosure vulnerabilities and 1 remote code execution vulnerability

Up next are patches that affect components of the Windows operating systems. These resolve over 25 vulnerabilities, including elevation of privilege, information disclosure, security feature bypass, remote code execution, and denial of service vulnerabilities. These vulnerabilities affect core Windows, Kernel, Media Center, Print Spooler, LSA, Network File System, Kerberos, and others.

Next are patches for the .NET and Visual Studio that resolve an information disclosure vulnerability.

Up next are patches that resolve information disclosure vulnerabilities in various Intel CPU families.

Lastly, administrators should focus on server-side patches for Hyper-V, LDAP, SharePoint, SQL Server, and Remote Volume Shadow Copy Service (RVSS). These resolve remote code execution and elevation of privilege vulnerabilities.

Microsoft Edge (Chromium-based)CVE-2022-22021
Microsoft OfficeCVE-2022-30172, CVE-2022-30171, CVE-2022-30159, CVE-2022-30174
Microsoft Office ExcelCVE-2022-30173
Microsoft WindowsCVE-2022-30131, CVE-2022-30135, CVE-2022-30147, CVE-2022-30136, CVE-2022-30148, CVE-2022-30140, CVE-2022-30167, CVE-2022-30193, CVE-2022-29119, CVE-2022-29111, CVE-2022-22018, CVE-2022-30188, CVE-2022-30151, CVE-2022-30155, CVE-2022-30162, CVE-2022-30152, CVE-2022-30150, CVE-2022-30166, CVE-2022-30142, CVE-2022-30189, CVE-2022-30164, CVE-2022-30165, CVE-2022-30145, CVE-2022-30132, CVE-2022-30160, CVE-2022-32230
.NET and Visual StudioCVE-2022-30184
IntelCVE-2022-21123, CVE-2022-21125, CVE-2022-21127, CVE-2022-21166
Role: Windows Hyper-VCVE-2022-30163
Remote Volume Shadow Copy Service (RVSS)CVE-2022-30154
Microsoft Office SharePointCVE-2022-30157, CVE-2022-30158
Windows LDAP – Lightweight Directory Access ProtocolCVE-2022-30149, CVE-2022-30141, CVE-2022-30143, CVE-2022-30161, CVE-2022-30146, CVE-2022-30139, CVE-2022-30153