We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Exploit:Python/CVE-2022-47986.A
Aliases: No associated aliases
Summary
This is the detection for python script that exploits CVE-2022-47986, a vulnerability in IBM Aspera Faspex. Attackers attempting to take advantage of the vulnerability could run arbitrary code on the device, caused by a YAML deserialization flaw.
- Remove any affected devices from the network and thoroughly investigate for any signs of a breach.
- If you have cloud-delivered protection, your device gets the latest defenses against new and unknown threats. If you don't have this feature turned on, update your antimalware definitions and run a full scan to remove this threat.
Apply the following mitigations to reduce the impact of this threat:
- A patch is available for CVE-2022-47986. Administrators should upgrade to version 4.4.2 PL (Patch Level) 2 to address the obsolete API call.
You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.