Microsoft Alert
3590Warning Date
Severity Level
Warning Number
Target Sector
9 November, 2022
● Critical
2022-5350
All
Microsoft has released security updates to address several vulnerabilities in the following products:
- Microsoft Exchange Server
- Windows 7
- Windows 8.1
- Windows 8.1 RT
- Windows 10
- Windows 11
- Windows Server 2008
- Windows Server 2012
- Windows Server 2016
- Windows Server 2019
- Windows Server 2022
An attacker could exploit these vulnerabilities by doing the following:
- Remote Code Execution by tricking the user to open a specially crafted website or server share allowing the attacker to execute commands
- Elevation of privilege that can be exploited locally with a low privileged user to gain SYSTEM privileges
- bypass the Mark of the Web (MOTW) security feature. They can craft a malicious file triggering the flaw and deliver it either via a malicious or compromised website or via email
The CERT team encourages users to review Microsoft security advisory and apply the necessary updates:
How to update Windows:
- https://support.microsoft.com/en-us/windows/get-the-latest-windows-update-7d20e88c-0568-483a-37bc-c3885390d212