myDRE is NOT vulnerable for CVE-2022-26809 - Serious Vulnerabilities in Microsoft Windows Workplaces and Servers

myDRE is NOT vulnerable for CVE-2022-26809 - Serious Vulnerabilities in Microsoft Windows Workplaces and Servers

Situation

Last “patch Tuesday” Microsoft disclosed and fixed a large number of serious vulnerabilities in Microsoft Windows. One of these vulnerabilities is identified as CVE-2022-26809 with a CVSS score of 9.8 (scale 1-10). CVE-2022-26809 is a vulnerability in Windows RPC, an attacker could exploit the vulnerability to remotely execute arbitrary code on a system. Exploit code for this vulnerability is expected to be released in the near future. The vulnerability is potentially "wormable". This means that the malware exploiting the vulnerability can easily copy and run itself from the 1st system to the other, without requiring any user interaction.

More information about this vulnerability can be found at the NCSC (https://advisories.ncsc.nl/advisory?id=NCSC-2022-0250) and Microsoft (https://msrc.microsoft.com/update-guide/vulnerability /CVE-2022-26809).


Assessment

  1. For the vulnerability to be exploited, inbound access is required.
  2. myDRE VMs at best have outbound access
  3. The exploit is assessed with: Due to lack of connectivity for the exploit is assessed with:
    1. Impact = HIGH
      1.  attackers can exploit a big port range over SMB instructions
    2. Severity = LOW
      1. Lack of connectivity with VMs from outside; inbound is blocked
    3. The above results in:
      1. Threat = LOW  => Priority = LOW

Actions

  1. A Product Backlog Item with Priority low/medium to patch this vulnerability