β€‹β€‹βœ…Π’Ρ‹ΡˆΠ»ΠΈ Π½ΠΎΡΠ±Ρ€ΡŒΡΠΊΠΈΠ΅ обновлСния для MS Windows, ΠΊΠΎΡ‚ΠΎΡ€Ρ‹Π΅ ΠΈΡΠΏΡ€Π°Π²Π»ΡΡŽΡ‚ ΠΊΠ°ΠΊ ΠΌΠΈΠ½ΠΈΠΌΡƒΠΌ 6 Π°ΠΊΡ‚ΠΈΠ²Π½ΠΎ ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡŽΡ‰ΠΈΡ…ΡΡ 0-day уязвимостСй!



А это Π·Π½Π°Ρ‡ΠΈΡ‚, Ρ‡Ρ‚ΠΎ

- ΠΆΠ΅Π»Π°Ρ‚Π΅Π»ΡŒΠ½ΠΎ ΠΎΠ·Π½Π°ΠΊΠΎΠΌΠΈΡ‚ΡŒΡΡ со списком ΠΎΠ±Π½ΠΎΠ²Π»Π΅Π½ΠΈΠΉ

- Π²Ρ‹ΠΏΠΎΠ»Π½ΠΈΡ‚ΡŒ Ρ€Π΅Π·Π΅Ρ€Π²Π½ΠΎΠ΅ ΠΊΠΎΠΏΠΈΡ€ΠΎΠ²Π°Π½ΠΈΠ΅ систСм, Π½Π° ΠΊΠΎΡ‚ΠΎΡ€Ρ‹Ρ… Π±ΡƒΠ΄ΡƒΡ‚ ΠΏΡ€ΠΎΠΈΡΡ…ΠΎΠ΄ΠΈΡ‚ΡŒ измСнСния

- ΠΏΠΎ возмоТности, произвСсти установку Π½Π° стСйдТСнговом стСндС ΠΈΠ»ΠΈ Π½Π° тСстовых ПК, для ΠΏΡ€ΠΎΠ²Π΅Ρ€ΠΊΠΈ Π½Π° Ρ€Π°Π±ΠΎΡ‚ΠΎΡΠΏΠΎΡΠΎΠ±Π½ΠΎΡΡ‚ΡŒ послС внСсСния ΠΈΠ·ΠΌΠ΅Π½Π΅Π½ΠΈΠΉ



Six actively exploited zero-days fixed:

CVE-2022-41128 - Windows Scripting Languages Remote Code Execution Vulnerability

CVE-2022-41091 - Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2022-41073 - Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2022-41125 - Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

CVE-2022-41040 - Microsoft Exchange Server Elevation of Privilege Vulnerability

CVE-2022-41082 - Microsoft Exchange Server Remote Code Execution Vulnerability



Π‘Ρ‚Π°Ρ‚ΡŒΠΈ для ознакомлСния:

- November 2022 Security Updates

- Microsoft November 2022 Patch Tuesday fixes 6 exploited zero-days, 68 flaws

- Released: November 2022 Exchange Server Security Updates





P.S. КоллСги ΠΈΠ· нашСго Ρ‡Π°Ρ‚ΠΈΠΊΠ° ΠΏΡ€Π΅Π΄ΡƒΠΏΡ€Π΅ΠΆΠ΄Π°ΡŽΡ‚βš οΈ



"However, since Windows 7 and Windows Server 2008 R2, DESCBCCRC and DESCBCMD5 are no longer supported as supported Kerberos encryption types. With the November 2022 updates, the default supported Kerberos encryption types in the operating system no longer include RC4HMACMD5." - послС Π½ΠΎΡΠ±Ρ€ΡŒΡΠΊΠΈΡ… ΠΎΠ±Π½ΠΎΠ²ΠΎΠΊ ΠΌΠΎΠ³ΡƒΡ‚ Π²ΠΎΠ·Π½ΠΈΠΊΠ½ΡƒΡ‚ΡŒ ΠΏΡ€ΠΎΠ±Π»Π΅ΠΌΡ‹ с линуксов, Ρ€Π°Π±ΠΎΡ‚Π°ΡŽΡ‰ΠΈΡ… с Kerberos Π² Π°ΠΊΡ‚ΠΈΠ²ΠΊΠ΅."



#Microsoft #PatchTuesday