February Patch Tuesday: CISOs should act now on two actively exploited Windows Server vulnerabilities

February Patch Tuesday: CISOs should act now on two actively exploited Windows Server vulnerabilities February Patch Tuesday: CISOs should act now on two actively exploited Windows Server vulnerabilities

“With SYSTEM-level access, attackers could install programs, view, change, or delete data, or create new accounts with full user rights, compromising the security and integrity of corporate systems,” noted Mike Walters, president of patch management provider Action1. 

Tyler Reguly, associate director of security R&D at Fortra, agreed. “While both vulnerabilities are rated Important by Microsoft and have CVSS (Common Vulnerability Scoring System) scores in the 7.x range, I would treat the Windows AFD for WinSock vulnerability as critical when it comes to patching, given that it has seen active exploitation,” he said in an interview.

This vulnerability has the potential to hit all three parts of the CIA (data confidentiality, integrity, and availability) triad, he added.

Add a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use