#Microsoft discloses a new critical #vulnerability (CVE-2022-37958) that rivals #EternalBlue where attackers can do remote code execution without #authentication and is #wormable.

Worst of all, unlike EternalBlue, this new vulnerability works on any network protocol, not just SMB. Microsoft has since patched this vulnerability back in September.

Be sure that all your systems have been patched!

https://arstechnica.com/information-technology/2022/12/critical-windows-code-execution-vulnerability-went-undetected-until-now/

Microsoft advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-37958

#Windows #vulnerabilitymanagement #infosec #cybersecurity
Akkoma

October Patch Tuesday: Microsoft Patches Critical, Wormable RCE Bug - There were 11 critical bugs and six that were unpatched but publicly known in this month's regular... https://threatpost.com/october-patch-tuesday-wormable-bug/160044/ #securityvulnerabilities #routeradvertisements #remotecodeexecution #publiclydisclosed #vulnerabilities #cve-2020-16898 #cloudsecurity #unpatchedbugs #patchtuesday #websecurity #october2020 #securitybug #microsoft #critical #wormable #patches #tcp/ip
October Patch Tuesday: Microsoft Patches Critical, Wormable RCE Bug

There were 11 critical bugs and six that were unpatched but publicly known in this month’s regularly scheduled Microsoft updates.

Threatpost - English - Global - threatpost.com
3-Month Apple Hack Turns Up 55 Vulnerabilities – 11 Critical

Ethical hackers so far have earned nearly $300K in payouts from the Apple bug-bounty program for discovering the flaws.

Threatpost - English - Global - threatpost.com
Microsoft Tackles 123 Fixes for July Patch Tuesday - Eighteen critical bugs, impacting Windows Server, Office and Outlook, were fixed as part of the pa... more: https://threatpost.com/microsoft-tackles-123-fixes-july-patch-tuesday/157440/ #windowsserversharedstreamlibrary #julypatchtuesday #vulnerabilities #adobecoldfusion #downloadmanager #genuineservice #cve-2020-1350 #cve-2020-1463 #cryptography #mediaencoder #deprecated #wormable #windows #dnsbug #google #tls1.0 #tls1.1
Microsoft Tackles 123 Fixes for July Patch Tuesday

Eighteen critical bugs, impacting Windows Server, Office and Outlook, were fixed as part of the patch roundup.

Threatpost - English - Global - threatpost.com
Wormable, Unpatched Microsoft Bug Threatens Corporate LANs - CVE-2020-0796 affects version 3.1.1 of Microsoft’s SMB file-sharing system and was not included in... more: https://threatpost.com/wormable-unpatched-microsoft-bug/153632/?utm_source=rss&utm_medium=rss&utm_campaign=wormable-unpatched-microsoft-bug #securityvulnerability #file-sharingsystem #vulnerabilities #cve-2020-0796 #version3.1.1 #eternalblue #microsoft #unpatched #wannacry #wormable #smb
Wormable, Unpatched Microsoft Bug Threatens Corporate LANs

CVE-2020-0796 affects version 3.1.1 of Microsoft’s SMB file-sharing system and was not included in Patch Tuesday.

Threatpost - English - Global - threatpost.com
Nearly half of hospital Windows systems still vulnerable to RDP bugs - Almost half of connected hospital devices are still exposed to the wormable BlueKeep Windows flaw ... more: https://nakedsecurity.sophos.com/2020/02/20/nearly-half-of-hospital-windows-systems-still-vulnerable-to-rdp-bugs/ #governmentsecurity #operatingsystems #securitythreats #medicaldevices #vulnerability #microsoft #bluekeep #dejablue #wormable #windows #worms #nhs
Nearly half of hospital Windows systems still vulnerable to RDP bugs

Naked Security