This January Microsoft published patches for critical vulnerabilities impacted data centers. Microsoft’s latest Patch Tuesday included fixes for 8 critical vulnerabilities covering Windows Server 2012, 2012 R2, Windows Server 2016 and 2019 and Windows 8.1 and Windows 10. Some of these vulnerabilities impact cryptographic certificates and components of the remote desktop service. These vulnerabilities allow attackers to attach remote desktop gateways without credentials and spoof encrypted HTTPS traffic and provide fake code signing certificates.

You can read more about these vulnerabilities in Guardicore Labs’ blog post here. The blog covers the impact of the Cryptographic Spoofing Vulnerability and of two RDP Vulnerabilities that collectively require careful attention to understand their scope and impact.

