Microsoft's July security update patches two vulnerabilities that attackers are already using against real businesses, including a flaw that can bypass BitLocker disk encryption.
- What it is: Two critical vulnerabilities were fixed in Microsoft's July update. One affects Active Directory Federation Services (AD FS) and SharePoint Server, the other lets attackers bypass BitLocker drive encryption.
- Who is affected: Businesses running on-premises Windows Server infrastructure, particularly those using AD FS for single sign-on or SharePoint Server, and any device relying on BitLocker to protect data on lost or stolen laptops.
- The risk: Both flaws are being actively exploited, meaning attackers already have working methods to take advantage of systems that have not been patched.
- What to do: Apply Microsoft's July security updates as soon as possible, and confirm with your IT provider that patching has completed on all affected servers and devices.
If you are unsure whether your systems have been patched, we recommend checking with your IT provider this week.