Oct 3, 2023

Skill Assessment - Windows Server


過去問題ソース

 https://www.chase2learn.com/windows-server-linkedin-assessment-answers/


以下、学習を深めるため、過去問ソース記載の解答を太字で、その下にChatGPT解答を記しておく。


Q1. You need to create a file share for your company 

that must be accessible from all branch offices and its share path must have the name Work Share. Which server role do you install?

1. BranchCache for Network Files

2. File Server

3. Work Folders

4. DFS Namespaces

 

ChatGPT解答

To create a file share for your company that is accessible from all branch offices with the share path named "Work Share," you should install the DFS Namespaces server role.

DFS (Distributed File System) Namespaces allows you to create a unified namespace that spans multiple servers and locations, making it easier to manage and access files across different branch offices.
You can use DFS Namespaces to create a share path like "\contoso.com\Work Share" that can be accessed from multiple locations seamlessly.

So, the correct answer is: 4. DFS Namespaces


次の下線部を追加して、再び尋ねてみた。過去問との食い違いが気になったし、"4. DFS Namespaces"は違和感があったので。


Q1. You need to create a file share on Microsoft Windows server 

for your company that must be accessible from all branch offices and its share path must have the name Work Share. Which server role do you install?

1. BranchCache for Network Files

2. File Server

3. Work Folders

4. DFS Namespaces

 

ChatGPT

To create a file share on a Microsoft Windows Server that is accessible from all branch offices with the share path named "Work Share," you should install the File Server role. The File Server role allows you to share files and folders on a Windows Server, making them accessible to users across your organization.

So, the correct answer is: 2. File Server


In this senario, what is the biggest difference between installing File Server role and DFS Namespaces?

 

ChatGPT

In the scenario of creating a file share accessible from all branch offices with the share path named "Work Share," the biggest difference between installing the File Server role and DFS Namespaces lies in their purpose and functionality:

1.     File Server Role:

    • The File Server role primarily focuses on sharing files and folders on a Windows Server.
    • It provides a straightforward way to create and manage file shares on a single server.
    • File Server role does not inherently provide advanced features for load balancing, redundancy, or easy access to files across multiple servers or locations.

2.     DFS Namespaces:

    • DFS Namespaces, or Distributed File System Namespaces, is a feature that allows you to create a unified namespace that spans multiple servers and locations.
    • It enables you to create a single share path (like "\contoso.com\Work Share") that abstracts the underlying server structure, making it appear as if all files are in one location, even if they are distributed across different servers.
    • DFS Namespaces provides advanced features like load balancing, fault tolerance, and the ability to easily access files from multiple servers, which is particularly useful in scenarios with branch offices.

In summary, the File Server role is suitable for simple file sharing on a single server, while DFS Namespaces is designed for more complex scenarios where you need to provide access to files across multiple servers and locations with advanced features for load balancing and redundancy. For the scenario you mentioned, where the goal is to make the share accessible from all branch offices, DFS Namespaces would be the more appropriate choice.


In this senario, how BranchCache for Network Files can contribute?

 

ChatGPT

In the scenario of creating a file share that must be accessible from all branch offices with the share path named "Work Share," BranchCache for Network Files can contribute by enhancing the performance and efficiency of accessing files over a wide area network (WAN) or slow network links, such as those connecting branch offices to the central server. Here's how BranchCache can be beneficial:

1.     Caching Content Locally: BranchCache allows branch office clients to cache a copy of frequently accessed files locally. When a user accesses a file from the central server for the first time, BranchCache can store a copy of that file on the local branch office client.

2.     Subsequent Faster Access: When other users in the same branch office need to access the same file, they can retrieve it from the local cache rather than downloading it again from the central server. This reduces WAN traffic and improves file access times for branch office users.

3.     Reduces WAN Bandwidth Utilization: By caching files locally, BranchCache helps reduce the load on the WAN link between branch offices and the central server. This is especially valuable in scenarios where bandwidth is limited or expensive.

4.     Automatic Synchronization: BranchCache can be configured to automatically synchronize cached content with the central server to ensure that users have access to up-to-date files while still benefiting from local caching.

5.     Security and Authentication: BranchCache maintains security and access controls, ensuring that only authorized users can access cached files.

In summary, BranchCache for Network Files is a technology that can significantly improve the performance and efficiency of accessing files over WAN or slow network links by caching frequently accessed files locally in branch offices. While DFS Namespaces focuses on providing a unified namespace for file access across multiple servers and locations, BranchCache complements it by optimizing the actual file access process, especially in scenarios where bandwidth constraints or latency are issues.


In that senario, what is the biggest difference between BranchCache for Network Files and DFS Namespaces?

 

ChatGPT

The biggest difference between BranchCache for Network Files and DFS (Distributed File System) Namespaces lies in their primary purposes and how they address different aspects of file access and optimization:

1.     BranchCache for Network Files:

·       Purpose: BranchCache is primarily designed to optimize the efficiency of file access over slow or bandwidth-constrained WAN links, especially in scenarios where branch offices need to access files from a central server.

·       Functionality: It accomplishes this by caching frequently accessed files locally in branch offices, allowing subsequent users to retrieve those files from the local cache instead of repeatedly downloading them over the WAN. This reduces WAN traffic and improves file access times.

·       Optimization Focus: BranchCache is focused on optimizing the actual file transfer process and minimizing the impact of WAN latency and bandwidth limitations.

2.     DFS Namespaces:

·       Purpose: DFS Namespaces is designed to provide a unified namespace for file access across multiple servers and locations. It abstracts the underlying server structure and presents a single share path to users, making it easier to manage and access files distributed across different servers.

·       Functionality: It offers features like load balancing, fault tolerance, and the ability to distribute files across multiple servers. DFS Namespaces enhances the scalability, availability, and organization of file shares.

·       Optimization Focus: DFS Namespaces optimizes the organization and accessibility of files across a network by providing a consistent, logical structure for file shares, but it does not directly address the optimization of file transfer over WAN links.

In summary, the key difference is that BranchCache focuses on optimizing the performance of file access over WAN links by caching files locally in branch offices, while DFS Namespaces focuses on creating a unified namespace for file access across multiple servers and locations. These technologies serve complementary roles in improving file access and management in networked environments, with BranchCache addressing the WAN optimization aspect and DFS Namespaces addressing the organization and accessibility of files across multiple servers.

 

以上から、Q1については過去問解答が正しいと考える(冒頭参照)。


Jul 1, 2023

マイナポイント環境チェックエラーでハマった件

準備からポイント申請までの手順を示す。 注意すべきポイントは●印箇所 

1.マイナンバーカードの読み取り装置を購入

ソニー NFC通信リーダー usb2.0 "PaSoRi" RC-S380/S パソコン用

2.読み取りソフトを導入

前述装置には同梱されてないので ...

2-1.「NFCポートソフトウェア」を入手

ドライバと自己診断ソフトからなる模様。 
『NFCポートソフトウェアは、NFCポート/パソリで動作するアプリケーションソフトウェア、ユーティリティソフトウェアを利用するために必要なソフトウェアです。
※ FeliCaポートソフトウェアは、NFCポートソフトウェア へ名称変更しました。
 ..  Version 6.2.1 / 約43MB / 2022年12月1日』 
VirusTotalでのチェックも忘れずに。 
・NFCPortWithDriver.exe    ac2b4129ed242af8c412e5a03ca9cb1f78a6db452f8bc501a788026ccc6d271a 
  Size 43.32 MB (エクスプローラでは44,359 KBと表示)

問題無ければ、インストールして次へ。

Windowsメニューから「NFCポート自己診断」を選択、起動して診断しておくと良い。

 

2-2.非接触ICカードリーダー/ライター PaSoRi(パソリ)のアプリケーション

インストールしておくと交通系ICカードの使用履歴が見れたりするらしい。
執筆時点では、特に何もダウンロード・インストールしなかった。

3.マイナポイント申込サイトでの準備 

次のサイトで申し込みに必要なソフトをさらに入手・導入と、情報登録など。
「自身の端末でマイナポイント申込み」→「パソコンで申込み」→「申込みがはじめての方」から、下記『「マイキーID作成・登録準備ソフト」をインストール』へ。

3-1.マイキーID作成・登録準備ソフト​​  

「インストール」ボタンを押して、ソフトをダウンロード、VirusTotalでチェック、インストールする。

・MKJSsetup.exe    
Size 22.61 MB dfa218fa1287d906c413a7ba3907891924a3d76af92edb47e5b373b672577e74

・次のコメントが見えたらひとまず無視。
『※ 2020年7月以前にインストールされた方は、再度インストールを行ってください。アンインストールは不要です。』  

・電子証明書の有効期限チェックを有効にした。
 ※ 次の有効期限差異に注意。
a.マイナカードは10年間、
b.電子証明書は5年間。
更新を忘れると面倒そう、と容易に想像できる。従って、この自動チェックはデフォルトでは無効になっているように見えるが、有効にしておくと有用だろう。  

 

3-2.ブラウザ拡張機能「マイナポイント」

まずは管理者権限でブラウザを起動
拡張機能「マイナポイント」をインストール

ここまでの手順で思い当たる事が無くても、下図の「事前セットアップ ×」ループになるなら、管理者権限でのブラウザ起動を試してみると良い。

※ 一般ユーザ権限のブラウザでも「マイナンバーカードを読み取ります」と表示され、なにやら機能している雰囲気なのだが・・・

※ そういえば「NFCポート自己診断」は起動の度に管理者パスワードを求めてくるのだった。下記参考サイトのおかげで気づけた。 


○普段使いのアカウントのブラウザの拡張機能「マイナポイント」が
 何故かインストール済み。 

 試行過程では念のため削除してインストールやり直したが、削除しても良いだろう。

○インストール後に、「JPKI利用者ソフト」を起動し、バージョンを確認する。
 ver3.3の場合、念のためアップデートすることに。
 最新版は次のサイトで入手可。    
  https://www.jpki.go.jp/download/win.html

 ・JPKIAppli03-05.exe

8123fa09046a9b1458cc77256a34dbceebd09759aa3d5548b181b08f4e55dd97
Size 25.95 MB 
Last Analysis Date 12 days ago 

起動して、「自分の証明書」で、証明書に氏名、住所等が正しく登録されているか確認もしておくと良い。

3-3.拡張機能「マイナポータル」

マイナポイント申請には不要な拡張機能のようだが、一連の手順でダウンロードしてしまったので、メモしておく。

次のサイトからダウンロード

VirusTotalでチェック

 ・MPASetup_Chrome.exe

879d4eb317ea2169a2b993d103ccab5d6bd90248140135eafe60199c2831417f
Size 5.05 MB
Last Analysis Date 11 days ago


4.マイナポイント申込  

健康保険証や公金受取口座など全部合わせて申し込むと20,000ポイントもらえる(執筆時)。

電子マネーはこんなにあるよ(執筆時)。

公金受取口座に支払ってくれるとか、いっそ日本円も電子化して互換性のある様々なデバイスで使えるようにしてくれば良いのだがなぁ。

使おうと思っていた電子マネーは、事前に利用者登録が必要。
利用者登録後、以降のマイナポイント申込手続きに使えるようになるのは翌日との事。

07/03 追記→

改めてマイナポイントのページへ。
 https://id.mykey.soumu.go.jp/mypage/MKCAS010/


※ 以降の手続きは「ブラウザをシステム管理者権限で起動」に比べれば、
  特に苦労もしないだろう。概略をメモしておく。


同ページの「はじめる」から ..

「カード登録」健康保険証と一体化公金受取口座」の三つを選んで申込み。

画面の指示に従い手続きを終えると、「公金受取口座を登録してください」と促される。

「マイナポータルアプリとブラウザ拡張機能を、両方インストールしてください。」との指示の通りに。

  ・MPASetup_Chrome.exe

879d4eb317ea2169a2b993d103ccab5d6bd90248140135eafe60199c2831417f
Size 5.05 MB
Last Analysis Date 11 days ago

前述インストール後、ブラウザの新しい Windowが開いて、ブラウザ拡張機能の「追加」を促される(下図)。


ブラウザ拡張機能追加を終え、以前の画面で「利用者登録/ログイン」の指示文通りに。

初回ログインの後、「利用者登録」に誘導される。

メール通知の設定他の後、「利用者登録」ボタンを押して完了。


「申請入力補助情報の登録」もお好みで。

※ リスク(カード紛失や更新手続きミスでの失効時にどうなるか)が簡潔に示されると良かったのだが。

「口座情報の登録完了」の画面の「マイナポイントサイトへ」を押下げ。

キャンペーン申込み状況を確認する。

「公金受取口座の登録」のみ「条件未達成」と表示されているが、「登録状況の反映には1日程かかる場合があります」との事で、明日再確認することにして、ひとまず終了。


Apr 14, 2023

Zero Trust Maturity Model

以下、末尾 Ref のサイトの機械翻訳である。


ゼロトラストは、ネットワークが危険にさらされているとみなされる中で、情報システムやサービスにおいて、正確で最小限の権限によるリクエストごとのアクセス決定を実施する際の不確実性を最小限に抑えるために設計された概念とアイデアの集合体です。その目的は、データやサービスへの不正アクセスを防止し、アクセス制御の実施を可能な限り細かくすることです。ゼロトラストは、時間と共に変化するユーザー、システム、データ、資産間のきめ細かなセキュリティ制御のために、場所中心のモデルから、よりデータ中心のアプローチへの移行を提示しています。これにより、セキュリティポリシーの開発、実装、実施、および進化をサポートするために必要な可視性が提供されます。より根本的には、ゼロトラストは、サイバーセキュリティをめぐる組織の哲学と文化を変える必要があるかもしれません。

 

CISA's Zero Trust Maturity Model Version 2.0

CISAのゼロ・トラスト成熟度モデルは、各省庁がゼロ・トラスト・アーキテクチャに移行する際に参照できる多くのロードマップの1つである。成熟度モデルは、ゼロトラスト戦略や実施計画の策定を支援し、CISAの各種サービスが機関全体のゼロトラストソリューションを支援する方法を提示することを目的としています。

 

成熟度モデルは、5つの柱と3つの横断的な能力を含み、ゼロトラストの基礎に基づいている。各柱の中で、成熟度モデルは、従来型、初期型、先進型、最適型のゼロ・トラスト・アーキテクチャの具体例を示しています。

 

ZTMMのバージョン1.0は、20219月にパブリックコメントの募集を開始しました。ゼロ・トラスト成熟度モデルのコメントへの応答は、バージョン1.0フィードバックに対応したコメントと修正を要約しています。

 

バージョン2.0は、20221月に発行されたOMB M-22-09へのアライメントを組み込んでいます。

 

ゼロトラスト成熟度モデル V2.0 をダウンロードするには、ここをクリックしてください

 

Federal Zero Trust Resource Hub

行政管理予算局(OMB)とCISAは、連邦政府民間行政機関(FCEB)向けの連邦ゼロ・トラストガイダンスに関する中央リポジトリを維持しています。このウェブサイトには、連邦ゼロ・トラスト戦略を含むゼロ・トラストに関する最新情報および追加リソースが含まれています。

 

Zerotrust.cyber.gov を調べるには、ここをクリックしてください

 

Applying Zero Trust Principles to Enterprise Mobility

CISAは、連邦政府機関やその他の組織がゼロ・トラストへの道を歩むのを支援するため、「Applying Zero Trust Principles to Enterprise Mobility」を発行しました。この新しい出版物は、モバイルデバイスの技術的進化とユビキタスな使用により、モバイルデバイスと関連する企業のセキュリティ管理機能に対する特別な配慮の必要性を強調しています。

 

このガイダンスは、最近発表されたOMBゼロトラスト実施テンプレートとCISAゼロトラスト成熟度モデルを補完するものであることを意図しています。

 

CISAは、連邦企業のモビリティプログラムの一部である可能性が高い、現在利用可能なモバイルセキュリティ技術にZT原則をどのように適用できるかを機関に知らせるために、エンタープライズモビリティへのゼロトラスト原則の適用を起草しました。CISAは、この文書を202237日から2022420日までパブリックコメントのために公開しました。CISAは、すべての回答者のコメントに感謝し、コメントの裁定とドキュメントの更新版の作成に取り組んでいます

 

エンタープライズモビリティへのゼロトラスト原則適用の文書を入手するには、ここをクリックしてください

 

Ref. Zero Trust Maturity Model | CISA


Mar 25, 2023

Windows 11標準ツールで編集した画像から元画像を復元できる

【参考】 

Pixelより影響大? Windows 11標準ツールで編集した画像から元画像を復元できると判明 (03/23)

https://internet.watch.impress.co.jp/docs/yajiuma/1487728.html


 Snipping Toolの過去情報消去不備の件、いかにもプログラマーがデバッグ目的でうっかりやってしまいそう。
 いやらしいことに、問題がパッチで修正された後も、それ以前にブログ等に投稿した画像は自動修正されない点に要注意。
とすると、win7, 8.x, 10では問題無いのかまで含めた検証が欲しいところ。
元記事英語にも触れられていないのが気がかりである。


・関連を連想させる記事

Pixelで編集した画像→元画像を復元できることが判明して騒動に。実証ツールも公開 (03/20)

https://internet.watch.impress.co.jp/docs/yajiuma/1487012.html


『Pixelシリーズに標準搭載されているスクリーンショット編集ツール「マークアップ」で行った塗りつぶしや切り抜きについて、加工後のPNGファイルを保存するときに元データが削除されない不具合 .. 

加工後のPNGファイルを手に入れた第三者が、オリジナルの内容を復元できてしまう .. 不具合自体は2021年に修正されているが、それ以前に加工された画像は今も復元が可能 .. 』


Google Pixelのスクリーンショット編集機能に脆弱性、個人情報の漏えいにつながる危険も (03/20)

https://gigazine.net/news/20230320-google-pixel-markup-vulnerability-acropalypse/


『同脆弱性は「aCropalypse」(CVE-2023-21036)と呼ばれており、Android向けの最新アップデートであるAndroid 13 QPRで修正 .. 

マークアップが搭載されたのは2018年にリリースされたAndroid 9から。

例えば、お財布アプリなどに表示されるクレジットカード情報を含むスクリーンショットを撮影し、個人情報を伏せるためにカード番号部分を黒塗り編集してSNSなどで共有したとします。マークアップの脆弱性を突けば、この編集済みのスクリーンショットを編集前の状態に復元することが可能です。

マークアップで編集した画像を復元することができる理由は、編集されたバージョンの画像が元のファイルと同じ場所に保存されるためです。


少なくともPixelシリーズの場合は、デバッグ目的でうっかりというのとは違う。

だからといって win 7, 8.x, 10での検証も依然望ましい。


Feb 27, 2023

K.E.V. Dec - Jan

 書きかけ ↓


2022-4262         Google Chromium V8 Engine

Google Chromium V8 Type Confusion Vulnerability

2022-12-05

Google Chromium V8 contains a type confusion vulnerability. Specific impacts from exploitation are not available at this time.

Google Chromium V8 には、型崩れの脆弱性が存在します。この脆弱性を利用した具体的な影響については、現時点では未定です。

Apply updates per vendor instructions by 2022-12-26       

https://chromereleases.googleblog.com/2022/12/stable-channel-update-for-desktop.html

 

CVE-2022-42475           Fortinet              FortiOS

Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

2022-12-13

Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests.

Fortinet FortiOS SSL-VPN の複数のバージョンには、ヒープベースのバッファオーバーフローの脆弱性があり、認証されていないリモートの攻撃者が、特別に細工したリクエストを介して任意のコードまたはコマンドを実行できる可能性があります。

Apply updates per vendor instructions by 2023-01-03

https://www.fortiguard.com/psirt/FG-IR-22-398

 

CVE-2022-27518           Citrix    Application Delivery Controller (ADC) and Gateway

Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability

2022-12-13

Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability which allows an attacker to execute code as administrator.

Citrix Application Delivery Controller (ADC) および Gateway  SAML SP または IdP 設定時に、攻撃者が管理者としてコードを実行できる認証回避の脆弱性が存在します。

Apply updates per vendor instructions by 2023-01-03

https://www.citrix.com/blogs/2022/12/13/critical-security-update-now-available-for-citrix-adc-citrix-gateway/

 

CVE-2022-42856           Apple    iOS

Apple iOS Type Confusion Vulnerability

2022-12-14

Apple iOS contains a type confusion vulnerability when processing maliciously crafted web content leading to code execution.

Apple iOS には、悪意を持って細工されたウェブコンテンツを処理する際に、コードが実行される型崩れの脆弱性が存在します。

Apply updates per vendor instructions by 2023-01-04

https://support.apple.com/en-us/HT213516

 

# ----------------------------------------------

CVE-2022-26500           Veeam Backup & Replication

Veeam Backup & Replication Remote Code Execution Vulnerability

2022-12-13

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.

Backup & ReplicationアプリケーションのVeeam Distribution Serviceは、未認証のユーザーが内部API機能にアクセスすることを許可します。リモートの攻撃者は、内部APIに悪意のあるコードのアップロードと実行につながる入力を送信する事が出来ます。

Apply updates per vendor instructions by 2023-01-03       

https://www.veeam.com/kb4288

 

CVE-2022-26501           Veeam Backup & Replication

Veeam Backup & Replication Remote Code Execution Vulnerability

2022-12-13

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.

Backup & ReplicationアプリケーションのVeeam Distribution Serviceは、未認証のユーザーが内部API機能にアクセスすることを許可します。リモートの攻撃者は、内部APIに入力を送信し、悪意のあるコードのアップロードと実行につながる可能性があります。

Apply updates per vendor instructions by 2023-01-03

https://www.veeam.com/kb4288

 

# ----------------------------------------------

CVE-2018-5430              TIBCO  JasperReports

TIBCO JasperReports Server Information Disclosure Vulnerability

2022-12-29

TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files.

TIBCO JasperReports Server には、認証されたユーザが、主要な設定ファイルを含むウェブアプリケーションのコンテンツに読み取り専用でアクセスすることができる脆弱性が存在します。

Apply updates per vendor instructions by 2023-01-19

https://www.tibco.com/support/advisories/2018/04/tibco-security-advisory-april-17-2018-tibco-jasperreports-2018-5430

 

CVE-2018-18809           TIBCO  JasperReports

TIBCO JasperReports Library Directory Traversal Vulnerability

2022-12-29

TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system.

TIBCO JasperReports Library には、ディレクトリトラバーサルの脆弱性があり、ウェブサーバのユーザがホストシステムのコンテンツにアクセスすることが可能です。

Apply updates per vendor instructions by 2023-01-19

https://www.tibco.com/support/advisories/2019/03/tibco-security-advisory-march-6-2019-tibco-jasperreports-library-2018-18809

 

# ----------------------------------------------

CVE-2022-44698           Microsoft           Defender

Microsoft Defender SmartScreen Security Feature Bypass Vulnerability

2022-12-13

Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.

Microsoft Defender SmartScreen には、セキュリティ機能回避の脆弱性があり、特別に細工された悪意のあるファイルを介して、攻撃者が Mark of Web (MOTW) の防御を回避することが可能です。

Apply updates per vendor instructions by 2023-01-03

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-44698

 

CVE-2022-41080           Microsoft           Exchange Server

Microsoft Exchange Server Privilege Escalation Vulnerability

2023-01-10

Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.

Microsoft Exchange Server には、特権の昇格を可能にする未指定の脆弱性が存在します。この脆弱性は、CVE-2022-41082 と連鎖し、リモートでコードが実行される可能性があります。

Apply updates per vendor instructions by 2023-01-31

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41080

 

CVE-2023-21674           Microsoft           Windows

Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability

2023-01-10

Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation.

Microsoft Windows Advanced Local Procedure Call (ALPC) には、権限昇格の可能性がある未特定の脆弱性が存在します。

Apply updates per vendor instructions by 2023-01-31

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-21674

 

# ----------------------------------------------