Skip to main content

CISA Removes Windows Vulnerability From 'Must-Patch' List Due to Buggy Update


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

By Eduard Kovacs on May 16, 2022

 

The US Cybersecurity and Infrastructure Security Agency (CISA) has temporarily removed a Windows flaw from its Known Exploited Vulnerabilities Catalog after it was informed by Microsoft that a recent update can cause problems on some types of systems.

The vulnerability in question is CVE-2022-26925, which Microsoft describes as a Windows LSA spoofing vulnerability. The issue was addressed with the May 2022 Patch Tuesday updates and Microsoft warned at the time that the vulnerability has been publicly disclosed and exploited in attacks.

 

>> Full Article <<

2 replies

russell.harris
Popular Voice
Forum|alt.badge.img+5

Ooops!


kleinmat4103
Popular Voice
Forum|alt.badge.img+6
  • Popular Voice
  • 512 replies
  • May 16, 2022

This is so frustrating, and far from the first time this has happened. In this case I had a client contact me directly about patching this vulnerability ahead of our normal schedule. I explained why we don’t patch immediately, but pushed it through for him. And then, on cue, patch to fix vulnerable authentication process breaks all authentication.

 

ugh.