Your apps and Windows devices could be facing a whole new kind of threat

Illustration of a laptop with a magnifying glass exposing a beetle on-screen



(Image credit: Shutterstock / Kanoktuch)

A critical flaw in Windows-powered datacenters and applications, which Microsoft fixed in mid-2022, remains unpatched in almost all vulnerable endpoints, putting countless users at risk of different malware, or even ransomware, attacks.

Cybersecurity researchers from Akamai published a proof-of-concept (PoC) for the flaw, and determined the high percentage of yet unfixed devices.

The vulnerability Akamai is referring to is CVE-2022-34689, a Windows CryptoAPI spoofing vulnerability that allows threat actors to authenticate, or sign code, as the targeted certificate. In other words, threat actors can use the flaw to pretend to be another app or OS and have those apps run without raising any alarms. 

Ignoring the patch

“We found that fewer than one percent of visible devices in data centers are patched, rendering the rest unprotected from exploitation of this vulnerability,” Akamai researchers said. 

Speaking to The Register, the researchers confirmed that 99% of endpoints were unpatched, but that doesn’t necessarily have to mean they’re vulnerable – there still needs to be a vulnerable app for the attackers to exploit. 

The flaw was given a 7.5 severity score, and labeled as “critical”. Microsoft released a patch in October 2022, but few users have applied it yet. 

“So far, we found that old versions of Chrome (v48 and earlier) and Chromium-based applications can be exploited,” the researchers said. “We believe there are more vulnerable targets in the wild and our research is still ongoing.”

When Microsoft originally patched the flaw, it said that there was no evidence of the vulnerability being exploited in the wild. However, now with the PoC publicly available, it’s safe to assume that different threat actors will start hunting for vulnerable endpoints (opens in new tab). After all, the methodology has been given to them on a silver platter, all they need to do is find a victim. 

Via: The Register (opens in new tab)

Sign up to theTechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read More
Clora Redner

Latest

AIONOS Highlights Enterprise AI Vision for APAC at GITEX AI ASIA 2026

SINGAPORE, Apr 10, 2026 - (ACN Newswire) - AIONOS, a Singapore-based enterprise AI company backed by InterGlobe Enterprises and Assago Group, is making a strong presence at GITEX AI ASIA 2026, taking place from 9 to 10 April at Marina Bay Sands, Singapore. The company’s participation reflects its increasing investment in the Asia Pacific region

‘I Was Immediately Admitted’ – Junior Pope’s Wife Recounts Husband’s Devastating Death

The wife of late Nollywood actor, JohnPaul Odonwodo, popularly known as Junior Pope , Jennifer Odonwodo, has recounted the devastating moment she received news of his death. Naija News reports that Jennifer, in a post via her Instagram page on Friday, described the incident as “the most devastating call” of her life and had assumed

NASA prepares for Artemis 2 return

WASHINGTON — The Artemis 2 mission is set for a final, fiery test when the spacecraft reenters April 10 ahead of a splashdown off the California coast. Artemis 2 will wrap up a mission lasting a little more than nine days with a tightly choreographed sequence of events in the mission’s final hour. It starts

CDL Launches $1.6B Perpetual Securities Programme and More APAC Real Estate Headlines

In today’s review of real estate news from around the region, City Developments Ltd launches a $2 billion perpetual securities programme with UOB as arranger, Ares Management expands its Japan logistics portfolio under the Marq brand with three newly acquired... Read More>> The post CDL Launches $1.6B Perpetual Securities Programme and More APAC Real Estate Headlines appeared

Newsletter

Don't miss

AIONOS Highlights Enterprise AI Vision for APAC at GITEX AI ASIA 2026

SINGAPORE, Apr 10, 2026 - (ACN Newswire) - AIONOS, a Singapore-based enterprise AI company backed by InterGlobe Enterprises and Assago Group, is making a strong presence at GITEX AI ASIA 2026, taking place from 9 to 10 April at Marina Bay Sands, Singapore. The company’s participation reflects its increasing investment in the Asia Pacific region

‘I Was Immediately Admitted’ – Junior Pope’s Wife Recounts Husband’s Devastating Death

The wife of late Nollywood actor, JohnPaul Odonwodo, popularly known as Junior Pope , Jennifer Odonwodo, has recounted the devastating moment she received news of his death. Naija News reports that Jennifer, in a post via her Instagram page on Friday, described the incident as “the most devastating call” of her life and had assumed

NASA prepares for Artemis 2 return

WASHINGTON — The Artemis 2 mission is set for a final, fiery test when the spacecraft reenters April 10 ahead of a splashdown off the California coast. Artemis 2 will wrap up a mission lasting a little more than nine days with a tightly choreographed sequence of events in the mission’s final hour. It starts

CDL Launches $1.6B Perpetual Securities Programme and More APAC Real Estate Headlines

In today’s review of real estate news from around the region, City Developments Ltd launches a $2 billion perpetual securities programme with UOB as arranger, Ares Management expands its Japan logistics portfolio under the Marq brand with three newly acquired... Read More>> The post CDL Launches $1.6B Perpetual Securities Programme and More APAC Real Estate Headlines appeared

India becomes third largest country for solar PV capacity

The MNRE said it is still aiming to achieve Prime Minister Modi’s pledge to reach 500GW of renewable energy and nuclear capacity on India’s grid by 2030. Total solar capacity has increased by 53.28 times since 2014, the MNRE said, rising from 2.82GW in March 2014 to over 150GW in March 2026. It said that

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand