Critical Vulnerability

SpearTip | April 15th, 2022

 

Critical Vulnerability Alert

During Microsoft’s most recent ‘Patch Tuesday’ announcement, its team shared information about the need to immediately patch a highly critical vulnerability, CVE-2022-26809. The issue exists within Microsoft’s Remote Procedure Call (RPC) communication protocol and has received a vulnerability score of 9.8/10 from the Common Vulnerability Scoring System (CVSS). RPC is a widely utilized operating system (OS) that dates to and remains active on Windows 7 and Server 2008 to the most current OS.

CVE-2022-26809 is a remote code execution (RCE) vulnerability, which is particularly dangerous as its exploitation provides threat actors the opportunity to deploy any malicious code, including ransomware, within the system and its connected environments. An additional worrisome aspect of this critical vulnerability is that it is exploitable without human interaction and capable of spreading automatically. The extensive use of these vulnerable systems could lead to major disruptions if not patched immediately.

Recommended Remediation

The first recommendation is to spread awareness of this critical vulnerability to all IT teams and clients who use RPC communication protocols. From there, it is necessary to quickly apply the Microsoft-issued security patch to all impacted systems to remediate the flaw. More specifically, block the perimeter firewall ports 135, 139, 445, and 593 to limit the total attack surface available to threat actors due to the CVE-2022-26809 vulnerability.

When a software vulnerability is publicized, threat actors will attempt to exploit it for profit, notoriety, or out of sheer malice before updates or patches are completed. At SpearTip, our certified engineers specialize in handling data breaches with one of the fastest response times in the industry. We continuously monitor companies’ data network infrastructure at our 24/7/365 Security Operations Centers for malicious activity, including unauthorized access through port vulnerabilities, such as with CVE-2022-26809. Our ShadowSpear Platform is an unparalleled resource that integrates with cloud, network, and endpoint devices to enhance the cyber posture of any company and provides optimal visibility in preventing future cyber threats.

If your company is experiencing a breach, call our Security Operations Centers at 833.997.7327 to speak directly with an engineer.

Categories

Connect With Us

Featured Articles

Comprehensive Overview of Ransomware
Overview of Ransomware from 2023
01 May 2024
CSA Warning
CSA Warning About Security Risks with Evolving Cloud and AI Tech
29 April 2024
Cyberattack on UnitedHealth's Change Healthcare
Cyberattack on UnitedHealth's Change Healthcare Results in Multi-Million Dollar Loss
26 April 2024
Industries Vulnerable to Cyberattacks
Industries Vulnerable to Cyberattacks in 2023
24 April 2024

See ShadowSpear in Action

Identify, neutralize, and counter cyberattacks - provide confidence in your security posture

Stay Connected With SpearTip

Inside the SOC Newsletter

View our articles that cover trending topics in cybersecurity with insights from our 24/7/365 Security Operations Center.

ShadowSpear Platform

Cybersecurity actors are working around the clock, shouldn’t your security team be too? Technology solutions and security controls fail for a number of reasons, poor deployment, improper implementation, or just no one monitoring the alerts.

ShadowSpear Demo

Experience ShadowSpear for yourself. Our lightweight, integrated solution will help you sleep easier at night and provide immediate confidence in your security posture.