A novel attack chain that allows adversaries to hijack Windows Server Update Services (WSUS), the trusted patch-management architecture widely deployed across enterprise environments. The research, published by SpecterOps researcher Beyviel David, demonstrates how organizations hosting WSUS on an external SQL Server database face a critical operational risk: attackers with local network access can coerce authentication, capture a database session, and mint malicious “updates” that domain-joined endpoints trust and execute automatically. Windows Server Update Services Into Backdoors Enterprise WSUS deployments frequently separate the update management server from its backend storage, hosting the SUSDB database on a...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!