SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Microsoft May 2022 Patch Tuesday Addresses 75 Vulnerabilities Including 3 Zero-Days

Microsoft May 2022 Patch Tuesday Addresses 75 Vulnerabilities Including 3 Zero-Days

Microsoft May 2022 Patch Tuesday has released security updates addressing a total of 75 detected vulnerabilities. On the other hand, 8 are classified as critical, 66 as important, and 1 as low severity. Microsoft may 2022 patch Tuesday products covered in the May security update include Remote Deskt...

May 10, 2022By Tanish Mahajan5 min read

Microsoft May 2022 Patch Tuesday has released security updates addressing a total of 75detected vulnerabilities. On the other hand, 8 are classified as critical, 66 as important, and 1 as low severity. Microsoft may 2022 patch Tuesday products covered in the May security update include Remote Desktop Client, Windows Active Directory, Windows Cluster Shared Volume (CSV), Windows Failover Cluster Automation Server, Windows Kerberos, Windows Kernel, Windows LDAP – Lightweight Directory Access Protocol and  Windows Network File System, etc.

Further, the Microsoft Local Security Authority Server (CVE-2022-26925) vulnerability has been exploited in the wild as a zero-day and is recommended to patch immediately. This can be done with an efficient patch management software.

Microsoft May 2022 Patch Tuesday Zero-day Vulnerability Fixed

CVE-2022-26925 – Windows LSA Spoofing Vulnerability. Furthermore, this flaw has received a CVSSv3 score of 8.1. According to Microsoft, “An unauthenticated attacker could call a method on the LSARPC interface and coerce the domain controller to authenticate to the attacker using NTLM. Besides this security update, it detects anonymous connection attempts in LSARPC and disallows it”. Nevertheless, successful exploitation will allow threat actors to intercept legitimate authentication requests and use them to gain elevated privileges. Microsoft recommends reading the PetitPotam NTLM Relay advisory to mitigate these attacks.

CVE-2022-22713 – Windows Hyper-V Denial of Service Vulnerability. However, this flaw has received a CVSSv3 score of 5.6. Successful exploitation requires an attacker to win a race condition. In fact, this flaw has been publicly disclosed, and exploitation is told to be complicated. That is, this flaw can be exploited remotely.

CVE-2022-29972 – Azure Data Factory and Azure Synapse pipelines Remote Code Execution Vulnerability. This flaw could let attackers execute remote commands in the Integration Runtime Infrastructure. This flaw exists in the Magnitude Simba Amazon Redshift ODBC Driver component. According to Microsoft, “IR is a compute infrastructure utilized by Azure Data Factory and Azure Synapse pipelines that provide data integration capabilities across network environments.”

Microsoft May 2022 patch Tuesday Critical Vulnerabilities Fixed

CVE-2022-22017 – Remote Desktop Client Remote Code Execution Vulnerability. Therefore, this flaw has received a CVSSv3 score of 8.8 and requires user interaction by the victim as an attacker needs to convince a targeted user to connect to a malicious RDP server. In brief, successful exploitation could lead the malicious server to execute code on the victim’s system in the context of the targeted user. Moreover, this flaw can be exploited remotely and need no form of authentication.

CVE-2022-26923 – Active Directory Domain Services Elevation of Privilege Vulnerability. Therefore, this flaw has received a CVSSv3 score of 8.8. and allows a low-privileged user to escalate their privileges to a domain administrator in a default Active Directory environment with the Active Directory Certificate Services (AD CS) server role installed.

CVE-2022-26931 – Windows Kerberos Elevation of Privilege Vulnerability. This vulnerability can be exploited remotely and requires simple authentication, but the flaw exists because the application does not correctly impose security restrictions in Windows Kerberos, bypassing security restrictions and allowing privilege escalation.

CVE-2022-26937 – Windows Network File System Remote Code Execution Vulnerability. Moreover, this flaw has received a CVSSv3 score of 9.8. Meanwhile, successful exploitation needs an unauthenticated attacker to make a specially crafted call to a Network File System (NFS) that leads to Remote Code Execution. Finally, this flaw can’t be exploited in NFSV4.1.

CVE-2022-23270, CVE-2022-21972 – Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability where successful exploitation requires an attacker to win a race condition, furthermore increasing complexity.

Microsoft Security Bulletin Summary For May 2022

  • .NET and Visual Studio
  • Microsoft Exchange Server
  • Microsoft Graphics Component
  • Microsoft Local Security Authority Server (lsasrv)
  • Microsoft Office
  • Microsoft Office Excel
  • Microsoft Office SharePoint
  • Microsoft Windows ALPC
  • Remote Desktop Client
  • Role: Windows Fax Service
  • Role: Windows Hyper-V
  • Self-hosted Integration Runtime
  • Tablet Windows User Interface
  • Visual Studio
  • Visual Studio Code
  • Windows Active Directory
  • Windows Address Book
  • Windows Authentication Methods
  • Windows BitLocker
  • Windows Cluster Shared Volume (CSV)
  • Windows Failover Cluster Automation Server
  • Windows Kerberos
  • Windows Kernel
  • Windows LDAP – Lightweight Directory Access Protocol
  • Windows Media
  • Windows Network File System
  • Windows NTFS
  • Windows Point-to-Point Tunneling Protocol
  • Windows Print Spooler Components
  • Windows Push Notifications
  • Windows Remote Access Connection Manager
  • Windows Remote Desktop
  • Windows Remote Procedure Call Runtime
  • Windows Server Service
  • Windows Storage Spaces Controller
  • Windows WLAN Auto Config Service

Affected products in Microsoft May 2022 Patch Tuesday

Product: Microsoft Windows


Product
: Microsoft Office

CVEs/Advisory: CVE-2022-29107, CVE-2022-29108, CVE-2022-29109, CVE-2022-29110
Impact
: Remote Code Execution and Security Feature Bypass
KBs
: 4484347, 4493152, 5002184, 5002187, 5002194, 5002195, 5002196, 5002199, 5002203, 5002204, 5002205, 5002207

Product: Visual Studio Code
CVEs/Advisory
: CVE-2022-30129
Impact
: Remote Code Execution

However SanerNow VM and SanerNow PM detect these vulnerabilities and automatically fix them by applying security updates. Moreover, use SanerNow and keep your systems updated and secure.

Featured Posts

Open CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials
CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

CVE Research

CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch
Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

CVE Research

Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

Four vulnerabilities added to CISA’s KEV catalog on September 9, 2026 show widely different timelines between public disclosure and formal exploitation-based prioritization, ranging from one day to 239 days.

Sep 24, 2026

Open TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

CVE Research

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

A chronological look at how a long-running China-nexus espionage cluster evolved from server-side exploitation to a chained Chrome/Windows zero-day kit — and what that shift signals.

Sep 24, 2026