Date
1 - 1 of 1
Windows SPNEGO vuln CVE-2022-37958 reclassified as Critical (RCE)
https://thehackernews.com/2022/12/microsoft-reclassifies-spnego-extended.html Now reclassified as Critical because of newly confirmed proof of remote code execution (RCE). Has been described as wormable. Windows 7 family (workstation class and server class OSes) and up affected. SPNEGO is used by SMB, RDP, and HTTP (and therefore, IIS). Covered by this week's Patch Tuesday patches. -- Royce |
|