This CVE has been splashed all over as being exploited in the wild, but as is so often the case, the extent of the spread, the actual vulnerability of individual workstations and the vulnerability of personal machines and workstations vs. servers has not been in the reportage, along with a lot of badly needed details.
According to 0Patch’s Mitja:
Mitja Kolsek (0patch Help Center)
May 11, 2022, 15:34 GMT+2
“It is likely that this is a re-spawn of the original PetitPotam vulnerability, based on the original researcher’s tweet (https://twitter.com/raphajohnsec/status/1524088436809940995). We’re gathering more information but if the vulnerability is indeed the same, our micropatches for PetitPotam already block the attack on Windows 7 and Server 2008 R2 (PetitPotam is only realistically exploitable against servers, not workstations).
“Otherwise, we’ll prepare a patch as soon as we get a POC.”
OK, this is what we need when there’s something serious afoot: The Who, What, Where, When, How, and Why of it all.
Far too often everyone is sent into a needless panic by poorly-written click bait eye grabbing articles in the security press that offer only partial info as to exactly who is threatened, where the outbreaks are, how many there are, how severe, what part of the globe, etc, etc.
I’ve always read this sort of thing with a grain of salt (while grinding it in my teeth), but yesterday a usually excellent source coughed out an article that was way below his usual standard, and was as bare of detail as the surface of Io.
People, we don’t need this kind of thing, and we ought to start kicking to the writers of it. Don’t send your readers into a panic with scantily-documented and badly sourced data; all it does is cause people who have no cause for alarm to do the Chicken Little thing, which is helpful to nobody. If they don’t have the info, they should say so, clearly and distinctly, right along with what they DO know.
/ close soapbox mode /close safety valve
Win7 Pro SP1 64-bit, Dell Latitude E6330 ("The Tank"), Intel CORE i5 "Ivy Bridge", 12GB RAM, Group "0Patch", Multiple Air-Gapped backup drives in different locations. Linux Mint Newbie
--
"The more kinks you put in the plumbing, the easier it is to stop up the pipes." -Scotty