Thousands at risk from critical RCE bug in legacy MS service | Computer Weekly

General News

Summary

More than 360,000 unique hosts appear to be at risk from three newly disclosed vulnerabilities – one of them rated as critical – in the legacy Microsoft Message Queuing (MSMQ) service, a Check Point researcher has warned. The service has not been updated for some time and for all intents and purposes, was end-of-lifed a few years ago, although it remains available and can easily be enabled via the Control Panel or a specific PowerShell command, and herein, said Li, lies the problem. Check Point is holding off publishing full technical details of the exploit at this stage to give users time to patch their systems. If you are an MSMQ user but cannot apply the patch right now, it is worth blocking inbound connections from untrusted sources to the vulnerable port using firewall rules. The April update also fixed CVE-2023-28252, a zero-day vulnerability in the Microsoft Common Log File System (CLFS) – which is being exploited as part of an attack chain delivering the Nokoyawa ransomware.

Classifications

industries
Retail
applications
Accounting and Taxes

AskAI Classifications

Labels
Cybersecurity Software Network Security Cloud Security

Linked Companies