Your review has been sent successfully

Microsoft Alert

3590
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

9 November, 2022

● Critical

2022-5350

All

Description:

Microsoft has released security updates to address several vulnerabilities in the following products:

  • Microsoft Exchange Server
  • Windows 7
  • Windows 8.1
  • Windows 8.1 RT
  • Windows 10
  • Windows 11
  • Windows Server 2008
  • Windows Server 2012
  • Windows Server 2016
  • Windows Server 2019
  • Windows Server 2022
Threats:

An attacker could exploit these vulnerabilities by doing the following:

  • Remote Code Execution by tricking the user to open a specially crafted website or server share allowing the attacker to execute commands
  • Elevation of privilege that can be exploited locally with a low privileged user to gain SYSTEM privileges
  • bypass the Mark of the Web (MOTW) security feature. They can craft a malicious file triggering the flaw and deliver it either via a malicious or compromised website or via email
Best practice and Recommendations:

The CERT team encourages users to review Microsoft security advisory and apply the necessary updates:

How to update Windows:

  • https://support.microsoft.com/en-us/windows/get-the-latest-windows-update-7d20e88c-0568-483a-37bc-c3885390d212
Last updated at 9 November, 2022

Rate the content

rate-icon
up icon