6 ms·
Windows 10 Urgent Update
- parliament32 7y agoLet me guess, they've discovered too many users turned Telemetry off so they're pushing an urgent update to re-enable it.
- enzanki_ars 7y agoNope: Remote code execution via RDP - https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1182 https://portal.msrc.microsoft.com/en-US/security-guidance/ad...
- olyjohn 7y agoI would guess the amount of people who care enough, and are able to successfully disable all Telemetry, and prevent it from being re-enabled is so small that Microsoft doesn't care. I would also be willing to bet that the majority of people who have it "disabled" are still sending back plenty of Telemetry. If you really care, your best option is to just not use Windows.
- RyanAF7 7y agoMost sensible answer.
- SanchoPanda 7y agoThey have lost my confidence as well after breaking* a Windows 7 machine I was using as an ad hoc server with updates that ammounted to little more than telemetry without announcing themselves as such. * Set off a crash loop in connection with my setup that had been pretty conservatively setup. It was fixable, but a nonsense problem to deal with.
- enzanki_ars 7y agoCVE-2019-1182: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1182 https://portal.msrc.microsoft.com/en-US/security-guidance/ad... Slightly more technical information from Wired: https://www.wired.com/story/dejablue-windows-bugs-worm-rdp/ https://www.wired.com/story/dejablue-windows-bugs-worm-rdp/ TL;DR: Remote Code Execution via RDP on all windows versions, including 7 and 10. Wired Quote: > "Microsoft today warned Windows users of seven new vulnerabilities in Windows that, like BlueKeep, can be exploited via RDP, a tool that lets administrators connect to other computers in a network. Of those seven bugs, Microsoft's advisory emphasized that two are particularly serious; like BlueKeep, they could be used to code an automated worm that jumps from machine to machine, potentially infecting millions of computers." > "Unlike BlueKeep, however, the new bugs—half-jokingly named DejaBlue by security researchers tracking it—don't merely affect Windows 7 and earlier, as the earlier RDP vulnerability did. Instead, it affects Windows 7 and beyond, including all recent versions of the operating system."
- groovybits 7y agoThinking of this in context to Win7 EOL approaching: I imagine the type of people who have RDP publicly exposed are the same type of people who will not be upgrading from Win7 anytime soon. I suspect we will see many exploits of this to come.
- londons_explore 7y agoMicrosoft really ought to develop their own worm, and use it to patch the flaw. They can release it on the same day as the regular updates, and scan the whole IPv4 address space every hour. That way, the pool of unpatched machines will be so tiny it isn't worth evil people trying to exploit it.
- kgwxd 7y agoWouldn't that be illegal? I hope so.
- groovybits 7y agoIts the same threat vector as BlueKeep, so I would imagine the prime exploitation window for Win7 (which was/is vulnerable to both) has already passed. A quick Shodan query already does what you're thinking.
- Someone1234 7y agoOnly if you have Remote Desktop Connection (RDS) enabled and exposed to the open internet. Which you shouldn't. To quote the CVE: > Disable Remote Desktop Services if they are not required. # > Block TCP port 3389 at the enterprise perimeter firewall If you're using a VPN or RD Gateway which have been best practice for tens of years, you're already insulated. I'd still patch but outside of business hours.
- cptskippy 7y agoI know people do that, what with cloud based VMs and all, but still... I don't get it.
- Someone1234 7y agoIt should be noted that AWS and other Cloud providers let you set up Security Groups containing specific IP addresses or ranges (i.e. just whitelist your static IP for SSH/RDS access). It isn't as secure as a VPN (and not as convenient), but definitely a stop-gap if you don't want to pay for Client VPN.
- supernintendo 7y agoIt’s usually to run some old, proprietary software that only has a Windows version.
- AnIdiotOnTheNet 7y ago"Old, proprietary software" describes something like 80% of all the software keeping the modern world going.
- AstralStorm 7y agoSome of it is new software. South Korean love of ActiveX for example, a technology dead for at least 10 years. Still getting new stuff written. On the contrary, most critical software is plenty new - things like MS Office. Still bound to Windows. The remaining systems rely on truly custom software and should be either airgapped (so no RDP) or rewritten. I'm thinking industrial - they should've planned for this many years beforehand. There were instances back when Windows XP was the main driver.
- hermitdev 7y agoAnyone know if the latest insider ring builds are affected, or what the minimum build number is to have the fix? I'm currently on build 18956 at home...
- AstralStorm 7y agoI had a feeling something like that was lurking which is why the roll-up was visible but not distributed yet by Windows Update. They were testing it for corporate users...