-
15 January 2022, 8:50 pm
#1
Server 2022, Server 2019 and IIS on Windows 10 special patch available
https://msrc.microsoft.com/update-gu...CVE-2022-21907
For anyone that uses Server 2019 or 2022 Microsoft has released a special patch for a specific vulnerability that is only present in very specific circumstances.
As was stated at sans.edu, even if you do not have IIS enabled but since it affects http.sys it could be exploited in situations where remote management or web services for devices is enabled.
https://isc.sans.edu/diary/A+Quick+C...1907+FAQ/28234
Keep in mind these are only very specific cases and I have verified that even default installs with IIS default installs do not have the affected services enabled, nor the registry key.
Rick
Universal4
-
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules