Patch Tuesday
Three 0days and a pre-auth RCE (CVSS 9.8) in Windows Server Update Service that deserves urgent attention
The bug is in the SPNEGO Extended Negotiation Security Mechanism – which essentially allows a client and server to negotiate the choice of security mechanism that they use.
Attackers are going after high-profile targets in the government and defense sectors, with phishing campaigns that use WebDAV and LOLBins to deploy malware
"It’s notable that the exploit first uses the NtQuerySystemInformation API to leak kernel addresses to user mode."