Medium CVSS: MEDIUM report

Analysis of Lazarus Group's Attack Targeting Windows Web Servers

Tracked since May 6, 2026

CVSS Breakdown

6
CVSS Base Score
MEDIUM
Attack Vector
N/A
Requires physical access to exploit.
CIA Impact
Confidentiality N/A
Integrity N/A
Availability N/A

Insurance Impact Assessment

🛡️
Moderate Impact

Medium-severity vulnerabilities generally have limited direct impact on coverage, but accumulations of unpatched medium findings can influence underwriting decisions.

Threat report published 2025-03-11T14:20:42.819Z. Types: threat-report. The Lazarus group has been targeting Windows web servers, particularly in South Korea, installing webshells and C2 scripts to use compromised servers as proxies. The attacks involve multiple stages, i

Assess your exposure

Is your organization vulnerable? Run a free domain exposure scan to check.

← Back to Threat Feed