• What does “Exploitation less likely” really mean?

    Home » Forums » Newsletter and Homepage topics » What does “Exploitation less likely” really mean?

    Author
    Topic
    #2297529

    All of Microsoft’s separately identified security holes – CVEs in the parlance – are given an “Exploitability Index” level. Microsoft’s official defin
    [See the full post at: What does “Exploitation less likely” really mean?]

    Viewing 0 reply threads
    Author
    Replies
    • #2297534

      Homeland Security issues rare emergency alert over ‘critical’ Windows bug
      https://techcrunch.com/2020/09/19/homeland-security-emergency-alert-critical-windows-bug/

      • #2297535

        That’s the Zerologon security hole, which I talked about on Sept 15.

        Yes, it’s a problematic bug that’s bound to be exploited pretty soon now. But it only affects servers, and it can only be used by an attacker after they’re already inside your network. And if you’ve been following along and have already installed the August patches, you’re protected.

        1 user thanked author for this post.
        • #2297538

          Absolutely. Sysadmins are paying attention to Zerologon.

          But I think the point here may be that what Microsoft considers critical and what government cyber warriors think is critical may be two different things. Does “Exploitation less likely” mean that Microsoft thinks it would take more that a script kiddie to use it?

          Microsoft’s judgment may be questionable at both ends of the spectrum.

          Group K(ill me now)
          1 user thanked author for this post.
    Viewing 0 reply threads
    Reply To: What does “Exploitation less likely” really mean?

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: