Your apps and Windows devices could be facing a whole new kind of threat

Illustration of a laptop with a magnifying glass exposing a beetle on-screen



(Image credit: Shutterstock / Kanoktuch)

A critical flaw in Windows-powered datacenters and applications, which Microsoft fixed in mid-2022, remains unpatched in almost all vulnerable endpoints, putting countless users at risk of different malware, or even ransomware, attacks.

Cybersecurity researchers from Akamai published a proof-of-concept (PoC) for the flaw, and determined the high percentage of yet unfixed devices.

The vulnerability Akamai is referring to is CVE-2022-34689, a Windows CryptoAPI spoofing vulnerability that allows threat actors to authenticate, or sign code, as the targeted certificate. In other words, threat actors can use the flaw to pretend to be another app or OS and have those apps run without raising any alarms. 

Ignoring the patch

“We found that fewer than one percent of visible devices in data centers are patched, rendering the rest unprotected from exploitation of this vulnerability,” Akamai researchers said. 

Speaking to The Register, the researchers confirmed that 99% of endpoints were unpatched, but that doesn’t necessarily have to mean they’re vulnerable – there still needs to be a vulnerable app for the attackers to exploit. 

The flaw was given a 7.5 severity score, and labeled as “critical”. Microsoft released a patch in October 2022, but few users have applied it yet. 

“So far, we found that old versions of Chrome (v48 and earlier) and Chromium-based applications can be exploited,” the researchers said. “We believe there are more vulnerable targets in the wild and our research is still ongoing.”

When Microsoft originally patched the flaw, it said that there was no evidence of the vulnerability being exploited in the wild. However, now with the PoC publicly available, it’s safe to assume that different threat actors will start hunting for vulnerable endpoints (opens in new tab). After all, the methodology has been given to them on a silver platter, all they need to do is find a victim. 

Via: The Register (opens in new tab)

Sign up to theTechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read More
Clora Redner

Latest

Embracer Will Spin-Off ‘Fellowship Entertainment’ Into Its Own Company

"this approach represents the most effective long-term solution" by Ollie Reynolds 40 mins ago Image: Amazon Game Studios Embracer has announced its intention to spin-off Fellowship Entertainment into its own company in 2027. In the press release, founder Lars Wingefors states that the approach "represents the most effective long-term solution" for Embracer, with the intention

2027 NFL Draft Prospect Interview: Mikey D’Amato, LB, Cal Poly

2027 NFL Draft Prospect Interview: Mikey D’Amato, LB, Cal Poly Name: Mikey D’Amato Position: LB College: Cal Poly Height: 6′ 0″ Weight: 235 lbs X: @mikeydamato2 Instagram: @mikey_damato_ What made you decide you wanted to be a football player? It’s kind of in my blood, my pops he actually played in the NFL so honestly

These Types Of Vehicles Typically Depreciate Faster Than Others

Every gearhead has been in this situation. You're surfing through eBay Motors or Facebook Marketplace looking for cars, either just for fun or because you want a new project, and you see it: a European luxury car like a Mercedes S-Class, a BMW 7 Series, or something wild like a Maserati. The price is really

Roundtables: Inside the Musk v. Altman Trial

Watch subscriber-only discussion going behind the scenes of the trial and the implications for the AI race. Available only for MIT Alumni and subscribers. Listen to the session or watch below Elon Musk lost his suit against OpenAI, in which he alleged CEO Sam Altman and President Greg Brockman had deceived him over the company’s

Newsletter

Don't miss

Embracer Will Spin-Off ‘Fellowship Entertainment’ Into Its Own Company

"this approach represents the most effective long-term solution" by Ollie Reynolds 40 mins ago Image: Amazon Game Studios Embracer has announced its intention to spin-off Fellowship Entertainment into its own company in 2027. In the press release, founder Lars Wingefors states that the approach "represents the most effective long-term solution" for Embracer, with the intention

2027 NFL Draft Prospect Interview: Mikey D’Amato, LB, Cal Poly

2027 NFL Draft Prospect Interview: Mikey D’Amato, LB, Cal Poly Name: Mikey D’Amato Position: LB College: Cal Poly Height: 6′ 0″ Weight: 235 lbs X: @mikeydamato2 Instagram: @mikey_damato_ What made you decide you wanted to be a football player? It’s kind of in my blood, my pops he actually played in the NFL so honestly

These Types Of Vehicles Typically Depreciate Faster Than Others

Every gearhead has been in this situation. You're surfing through eBay Motors or Facebook Marketplace looking for cars, either just for fun or because you want a new project, and you see it: a European luxury car like a Mercedes S-Class, a BMW 7 Series, or something wild like a Maserati. The price is really

Roundtables: Inside the Musk v. Altman Trial

Watch subscriber-only discussion going behind the scenes of the trial and the implications for the AI race. Available only for MIT Alumni and subscribers. Listen to the session or watch below Elon Musk lost his suit against OpenAI, in which he alleged CEO Sam Altman and President Greg Brockman had deceived him over the company’s

Interview: How Volvo built software for a two-and-a-half-tonne moving object

Anders Bell points to his grey hair and laughs. “Three years ago, it was still blond and curly,” says Volvo’s chief engineering and technology officer. The remark is more than self-deprecating. It captures what Volvo has been through: five years of building a software-defined vehicle (SDV) from scratch, as a traditional carmaker, with no blueprint

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand