Critical Infrastructure Security

Extensive Compromise Likely With Windows CE Flaws

(Microsoft)

Industrial and healthcare organizations, as well as vending machines, automotive infotainment systems, and public kiosks using the Windows CE OS were discovered by Claroty Team82 researchers to be at risk of significant compromise involving newly-discovered vulnerabilities that would no longer be addressed as the OS has long reached end-of-life, SC Media reports.

Massive challenges associated with securing long-established Windows CE-based industrial systems should prompt such systems to be air-gapped to avert potential compromise, according to Thomas Richards, principal consultant and network and red team practice director at Black Duck.

"The long-term goal should be to upgrade these systems with modern OSes that receive regular updates and are not prone to known vulnerabilities," noted Richards.

You can skip this ad in 5 seconds