Report Incident
× Home Cybertech Africa 2023 2 DPO Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Alert: Microsoft Security Patches

Microsoft released security updates to fix found vulnerabilities in their software products and features that include, but not limited to:
  • Windows Server: 2012, 2016, 2019 and 2022
  • Exchange Server: 2013, 2016 and 2019
  • Windows OS: 10 and 11
  • Microsoft Edge
 
The released security updates fix about 96 vulnerabilities that include some rated as critical or important vulnerabilities, such as:
  • CVE-2022-21882: Microsoft Win32k Privilege Escalation Vulnerability
  • CVE-2022-21907: HTTP Protocol Stack Remote Code Execution Vulnerability
  • CVE-2022-21919: Windows User Profile Service Elevation of Privilege Vulnerability
 
Security Risks
If the identified vulnerabilities in Microsoft products are not patched, authenticated attackers can gain control of vulnerable systems and run malicious code with elevated privileges.
For the full list of security patches released by Microsoft, please refer to Microsoft Security Update Guide
 
Recommended Actions
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
  1. apply the latest security patches, as soon as possible, to prevent unauthorized control over unpatched systems;
  2. upgrade immediately to the latest supported version of installed Microsoft software in order to continue receiving technical support and security patches.
The following Microsoft software products reached their end-of-life and need to be upgraded immediately:
  • Windows XP, 8 and 7;
  • Exchange Server 2010;
  • and Windows Server 2008, 2008 RE;
     3. Before any update task, ensure you have backup for your data.
 
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009
 
References

January 2022 Security Updates
Security Update Guide

07 February 2022

© 2025 National Cyber Security Authority