iTnews Asia
  • Home
  • News
  • Security

Patch Wednesday fixes two-year-old Dogwalk vulnerability

Patch Wednesday fixes two-year-old Dogwalk vulnerability

Path traversal bug in diagnostics tool could be used for remote code execution.

By Juha Saarinen on Aug 10, 2022 8:44AM

Microsoft has fixed a remote code execution vulnerability in its MSDT diagnostics tool for Windows, first reported to the company two years ago and rediscovered in May this year.

The fix is part of this month's Patch Wednesday and was named Dogwalk by security researchers.

Although researcher Imre Rad reported the bug to Microsoft in January 2020, and despite the vulnerability raising its head again this year, the software giant initially declined to fix the issue.

Now, however, Microsoft has had a change of heart, according to the company's security researcher Johnathan Norman.

We finally fixed the #DogWalk vulnerably. Sadly this remained an issue for far too long. thanks to everyone who yelled at us to fix it @j00sean @ImreRad

— Johnathan Norman (@spoofyroot) August 9, 2022

After the Dogwalk vulnerability resurfaced in May this year, and exploitation attempts were recorded by Microsoft, the company issued workaround guidance for users.

August Patch Wednesday handles a record 141 vulnerabilities in different Microsoft products.

Among these is an information leak bug that affects the Exchange Server, given the Common Vulnerabilities and Exposures index of CVE-2022-30134.

Attackers exploiting the bug can read emails, Microsoft warned.

Simply patching isn't enough to handle the above vulnerability above, and others affecting Exchange Server.

Microsoft said administrators need to enable the Windows Extended Protection feature on Exchange Servers to fully handle the vulnerabilities.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
dogwalk microsoft patch wednesday security software

Related Articles

  • How making identity a priority can help bring clarity to AI chaos
  • Five tips a CIO or CSO should know to stop employee-driven IP theft
  • StarHub launches app to protect customers from scam calls and SMS
  • Beware the rise of ‘vishing’ as a cyber threat in APAC
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Five tips a CIO or CSO should know to stop employee-driven IP theft

Five tips a CIO or CSO should know to stop employee-driven IP theft

How can we bolster our resilience against AI-enabled e-mail attacks?

How can we bolster our resilience against AI-enabled e-mail attacks?

The real-life Tom & Jerry chase

The real-life Tom & Jerry chase

Beware the rise of ‘vishing’ as a cyber threat in APAC

Beware the rise of ‘vishing’ as a cyber threat in APAC

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.