Domain-joined clerk PCs remain missing a published OS security update that enables local privilege escalation, and attackers who phish one user become local admins. Which vulnerability class best describes the missing fix?
Select an answer to reveal the explanation.
Short Explanation
Missing the OS privilege-escalation patch means the operating system itself is the soft spot — classic OS-based vulnerability. Patch management is the cure, not blaming a public bucket or a map image. Keep clerk fleets current so phishing does not equal instant admin.
Full Explanation
Unpatched operating-system flaws, including privilege-escalation bugs, are OS-based vulnerabilities addressed through timely patch management. Objective 2.3 distinguishes OS-based issues from cloud misconfigurations, image vectors, and MSP supply-chain compromises. Municipal domain-joined fleets should track OS advisories, test, and deploy updates within defined SLAs.