News

Microsoft Warning: Patch 'Old' Versions of Windows

Giulio Saggin
Giulio Saggin
Tuesday 28 November 2023

"We strongly advise that all affected systems should be updated as soon as possible."

That's the message from Microsoft concerning a critical Remote Code Execution vulnerability, CVE-2019-0708, in Remote Desktop Services (formerly known as Terminal Services) that is able to infect older versions of Windows - Windows XP, Windows Vista, Windows 7, Windows 2003, Windows 2008 and Windows 2008 R2 (patches have been made available for all these).

The nature of the vulnerability (also known as BlueKeep) means it is able to self-replicate and spread to other computers in a network, and attackers can remotely run code on infected computers. Any malware that could exploit the vulnerabiltiy could have the same effect as WannaCry.

Many are yet to take heed of Microsoft's alert to update their software, even though the vulnerability and accompanying warnings were first made public during Microsoft's Patch Tuesday updates on May 14.

"If recent reports are accurate, nearly one million computers connected directly to the internet are still vulnerable. It only takes one vulnerable computer connected to the internet to provide a potential gateway into corporate networks, where advanced malware could spread, infecting computers across the enterprise," said Simon Pope, Director of Incident Response, Microsoft Security Response Center (MSRC).

Pope also warned that because there have been no attacks so far, it isn't reason to be complacent.

"It's been only two weeks since the fix was released and there has been no sign of a worm yet. This does not mean that we're out of the woods. It's possible that we won't see this vulnerability incorporated into malware. But that's not the way to bet."

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203