Moneycontrol PRO
Outskill Genai
HomeNewsTechnologyAnother EternalBlue-like flaw threatens Windows PCs

Another EternalBlue-like flaw threatens Windows PCs

The new vulnerability has not been named yet and is tracked as CVE-2022-37958

December 22, 2022 / 19:13 IST
Representative Image

Security researchers have discovered a new Windows vulnerability, with the potential to rival the damage caused by EternalBlue and WannaCry.

Like the previous attacks, the unnamed vulnerability (CVE-2022-37958) can allow threat actors to execute malicious code on a Windows system bypassing the authenticity checks.

Like EternalBlue and WannaCry, this new attack can spread to other vulnerable systems in a matter of minutes with no user interaction required.

While EternalBlue exploits were based on printer and file-sharing networks, the new loophole is even more dangerous since it can spread over a broader range of network protocols, making it more flexible and dangerous.

“An attacker can trigger the vulnerability via any Windows application protocols that authenticates,” said Valentina Palmiotti, security researcher at IBM, in an interview to Ars Technica.

“For example, the vulnerability can be triggered by trying to connect to an SMB share or via Remote Desktop. Some other examples include Internet exposed Microsoft IIS servers and SMTP servers that have Windows Authentication enabled. Of course, they can also be exploited on internal networks if left unpatched,” Palmiotti added.

The good news is that there is already a fix and Microsoft rolled out a patch for it in September but had marked its designation as "important" in the disclosure.

Palmiotti found out that the flaw allowed for remote execution, and informed Microsoft. The team then changed the designation to "critical" along with a rating of 8.1, the same rating as EternalBlue.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

first published: Dec 22, 2022 07:00 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347