The US Cybersecurity and Infrastructure Security Agency (CISA) ordered all federal agencies to patch a critical privilege escalation flaw that affects Windows servers and could allow hackers to take over Windows networks. A patch has existed for the vulnerability since August, but recently released technical details allowed hackers to create easy-to-use exploits. In particular, the vulnerability allows an attacker to impersonate any computer to the domain controller and change their password. This results in the attacker gaining administrative access and taking full control of the network.”]

