Decade-old vulnerability among 129 Patch Tuesday fixes
Summary
To function it must interact with many different components of the network, making it an important stress point and an ideal target for an attacker to help them strengthen their hold within an organisation,” said CyberArk’s Eran Shimony in a disclosure blog. “It also dramatically reduces the attack cycle, allowing a relatively easy jump to gain privileged access to critical systems.” It affects any Windows machine made since 2008, potentially meaning hundreds of millions of devices may be at risk if not properly patched. A total of 98 of them centre on Windows operating system (OS) and browser updates, with the remaining 31 spread across Office, SharePoint, Defender, Endpoint Protection, and developer tools including Visual Studio, ChakraCore and Azure DevOps. “With many organisations continuing to stretch existing resources to support the last-minute pivot to a more distributed work model, attackers will look to target applications that are core to business operations. “The shift to remote work introduced additional challenges and exposure for both IT and security operations, leading many to seek out more efficient, scalable endpoint management solutions that can keep pace with a constantly changing threat landscape.