Critical Vulnerability

SpearTip | April 15th, 2022

 

Critical Vulnerability Alert

During Microsoft’s most recent ‘Patch Tuesday’ announcement, its team shared information about the need to immediately patch a highly critical vulnerability, CVE-2022-26809. The issue exists within Microsoft’s Remote Procedure Call (RPC) communication protocol and has received a vulnerability score of 9.8/10 from the Common Vulnerability Scoring System (CVSS). RPC is a widely utilized operating system (OS) that dates to and remains active on Windows 7 and Server 2008 to the most current OS.

CVE-2022-26809 is a remote code execution (RCE) vulnerability, which is particularly dangerous as its exploitation provides threat actors the opportunity to deploy any malicious code, including ransomware, within the system and its connected environments. An additional worrisome aspect of this critical vulnerability is that it is exploitable without human interaction and capable of spreading automatically. The extensive use of these vulnerable systems could lead to major disruptions if not patched immediately.

Recommended Remediation

The first recommendation is to spread awareness of this critical vulnerability to all IT teams and clients who use RPC communication protocols. From there, it is necessary to quickly apply the Microsoft-issued security patch to all impacted systems to remediate the flaw. More specifically, block the perimeter firewall ports 135, 139, 445, and 593 to limit the total attack surface available to threat actors due to the CVE-2022-26809 vulnerability.

When a software vulnerability is publicized, threat actors will attempt to exploit it for profit, notoriety, or out of sheer malice before updates or patches are completed. At SpearTip, our certified engineers specialize in handling data breaches with one of the fastest response times in the industry. We continuously monitor companies’ data network infrastructure at our 24/7/365 Security Operations Centers for malicious activity, including unauthorized access through port vulnerabilities, such as with CVE-2022-26809. Our ShadowSpear Platform is an unparalleled resource that integrates with cloud, network, and endpoint devices to enhance the cyber posture of any company and provides optimal visibility in preventing future cyber threats.

If your company is experiencing a breach, call our Security Operations Centers at 833.997.7327 to speak directly with an engineer.

Categories

Connect With Us

Featured Articles

Ransomware Experiments
Ransomware Experiments on Developing Countries
15 May 2024
Credential Stuffing Attacks
Credential Stuffing Attacks Using TOR: Okta Warning
13 May 2024
Cybersecurity Gap
Close Cybersecurity Gaps through Analysis and Architecture Review
10 May 2024
“As Services” Industry
“As Services” Industry Evolved Ransomware Groups
08 May 2024

See ShadowSpear in Action

Identify, neutralize, and counter cyberattacks - provide confidence in your security posture

Stay Connected With SpearTip

Inside the SOC Newsletter

View our articles that cover trending topics in cybersecurity with insights from our 24/7/365 Security Operations Center.

ShadowSpear Platform

Cybersecurity actors are working around the clock, shouldn’t your security team be too? Technology solutions and security controls fail for a number of reasons, poor deployment, improper implementation, or just no one monitoring the alerts.

ShadowSpear Demo

Experience ShadowSpear for yourself. Our lightweight, integrated solution will help you sleep easier at night and provide immediate confidence in your security posture.