Menu

Blog

Jul 12, 2022

CISA orders agencies to patch new Windows zero-day used in attacks

Posted by in category: security

Saúl Morales RodriguézAuthor


CISA has added an actively exploited local privilege escalation vulnerability in the Windows Client/Server Runtime Subsystem (CSRSS) to its list of bugs abused in the wild.

This high severity security flaw (tracked as CVE-2022–22047) impacts both server and client Windows platforms, including the latest Windows 11 and Windows Server 2022 releases.

Microsoft has patched it as part of the July 2022 Patch Tuesday, and it classified it as a zero-day as it was abused in attacks before a fix was available.

Leave a reply