HomeSecurityCISA to organizations: Fix this zero-day vulnerability immediately

CISA to organizations: Fix this zero-day vulnerability immediately

CISA has added a serious privilege escalation vulnerability (CVE-2022-22047) to the list of exploits being exploited in attacks, located in the Windows Client/Server Runtime Subsystem ( CSRSS ) .

CISA vulnerability

This very serious vulnerability affects server and client Windows platforms, including the latest versions of Windows 11 and Windows Server 2022.

Microsoft fixed the vulnerability yesterday, with the release of Patch Tuesday July 2022 , and classified it as a zero-day, since it had been used in attacksbefore there was an official patch update to fix it.

Learn more: Microsoft Patch Tuesday July 2022: Fixes 84 vulnerabilities

"An attacker who successfully exploited this vulnerability could gain SYSTEM privileges," Microsoft explained.

According to the company, the vulnerability was discovered internally by researchers at the Microsoft Threat Intelligence Center (MSTIC) and the Microsoft Security Response Center (MSRC).

CISA: You have three weeks to update systems

CISA gave federal agencies three weeks (until August 2) to patch the CVE-2022-22047 vulnerability and block ongoing attacks that could target their systems.

See also: Apple Beta iOS 16, macOS Ventura, watchOS 9 are ready for download

Under a binding operational directive (BOD 22-01) issued in November, all Federal Civilian Executive Branch Agencies (FCEB) are required to protect their networks from vulnerabilities added to CISA's list of flaws actively exploited by attackers.

CVE-2022-22047

Although BOD 22-01 only applies to US federal agencies, CISA to also urges all agencies across the US to patch this Windows CSRSS flaw gain access to unpatched Windows systems.

“These types of vulnerabilities are a common attack vector for cybercriminals and pose a significant risk to federal business,” the US cybersecurity agency explained.

See also: New Bluetooth LE Audio features coming to wireless headphones

Since BOD 22-01 was issued, CISA has added hundreds of vulnerabilities to the list of bugs used in attacks and has asked US federal agencies to patch their systems as soon as possible to prevent breaches.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS