Microsoft's July update fixes three zero-day flaws

Microsoft's July Patch Tuesday resolves more than 570 vulnerabilities, including three zero-day flaws, two of which are being actively exploited. One of the exploited vulnerabilities affects on-premises Microsoft SharePoint Server, prompting CISA to urge organisations to apply the updates immediately, enable AMSI integration where possible, and review SharePoint servers for signs of compromise. Organisations with internet-facing SharePoint deployments should treat this as the top priority.

What this means for you if you own the patching cycle

More than 570 vulnerabilities is not a list you work through by hand. That is precisely why it is worth noting which two are being actively exploited. That is where we think your risk sits right now. The rest can follow your ordinary cycle.

We would add that the prioritisation itself carries value beyond reducing risk. If your organisation is in scope of NIS2, documented vulnerability prioritisation is a requirement in itself, not merely good practice. Making the right calls is then not enough on its own. You have to be able to show why you made them.

Berigo recommends

  • Prioritise the actively exploited flaws first, particularly on internet-facing SharePoint servers.
  • Enable AMSI integration on SharePoint where possible.
  • Review SharePoint servers for signs of compromise rather than simply patching them.
  • Maintain a written, approved rule for how quickly critical and actively exploited vulnerabilities must be remediated.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch