vuln-advisorystandardsNewsThe Broadside2 min read

Microsoft patches 40-plus products, including SQL and LSASS

The hard part is not deciding whether to patch, but sequencing domain, database, endpoint and customer environments without leaving crown jewels exposed.


TL;DR

Microsoft issued September 9 patches for more than 40 products, with MS-ISAC warning that the most severe vulnerabilities could allow remote code execution. Contractors, primes, subs and managed service providers should prioritize SQL Server, Windows PowerShell, Office, LSASS and SMBv3 exposures. MS-ISAC says it has no reports of exploitation in the wild, but the advisory does not specify CVSS scores, exploit timing or Windows Server 2019 and 2022 patch coverage.

MS-ISAC’s September 9 advisory is a straight patch-now item, but the breadth matters. Microsoft’s affected list spans SQL Server, Azure Windows Virtual Machine Agent, Windows PowerShell, Microsoft Edge, Routing and Remote Access Service, Internet Information Services, Windows Defender Firewall Service, Local Security Authority Subsystem Service, Hyper-V, TCP/IP, SMBv3 Client, Office, SharePoint, NTLM and other Windows components. The most severe vulnerabilities could allow remote code execution, and successful exploitation could give an attacker the privileges of the logged-on user.

For defense contractors and federal suppliers, that product mix cuts across the systems teams usually try to patch in separate lanes: identity infrastructure, file-sharing paths, databases, productivity software and managed endpoints. If the compromised user has administrative rights, MS-ISAC says an attacker could install programs, view, change or delete data, or create accounts with full user rights. Least privilege is not decorative control language here. It is the difference between a bad endpoint event and a domain-level cleanup.

MS-ISAC says there are currently no reports of exploitation in the wild. That helps triage, but it does not make this a narrow workstation update. Primes and managed service providers with hybrid estates or customer-administered enclaves have the usual patch-cycle problem in a sharper form: SQL and Active Directory-adjacent services do not move on the same maintenance window as Office clients, and customer systems often move slower than contractor-owned systems.

The advisory’s operational gap is also worth noting. It points readers to Microsoft for the full vulnerability list, but the CIS text itself does not provide CVSS scores, an exploit-availability timeline, or explicit patch coverage for Windows Server 2019 and 2022 editions. Monday’s work is inventory first, then phased deployment: identify exposed SQL, LSASS, SMBv3, Office and PowerShell footprints, patch after testing, and verify that privileged accounts are not turning a routine Microsoft month into an avoidable incident.


Published ·Deep Fathom