#Microsoft discloses a new critical #vulnerability (CVE-2022-37958) that rivals #EternalBlue where attackers can do remote code execution without #authentication and is #wormable.
Worst of all, unlike EternalBlue, this new vulnerability works on any network protocol, not just SMB. Microsoft has since patched this vulnerability back in September.
Be sure that all your systems have been patched!
https://arstechnica.com/information-technology/2022/12/critical-windows-code-execution-vulnerability-went-undetected-until-now/
Microsoft advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-37958
#Windows #vulnerabilitymanagement #infosec #cybersecurity
Worst of all, unlike EternalBlue, this new vulnerability works on any network protocol, not just SMB. Microsoft has since patched this vulnerability back in September.
Be sure that all your systems have been patched!
https://arstechnica.com/information-technology/2022/12/critical-windows-code-execution-vulnerability-went-undetected-until-now/
Microsoft advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-37958
#Windows #vulnerabilitymanagement #infosec #cybersecurity