3 ms·
In 2019, Microsoft released a patch for WinXP because there was a remote code execution vulnerability, and there were enough WinXP machines still around to make
by sp332 2y ago
In 2019, Microsoft released a patch for WinXP because there was a remote code execution vulnerability, and there were enough WinXP machines still around to make this a big deal. A machine without this one patch would still be immediately vulnerable.
- miles 2y agoWas this remotely exploitable with the firewall on (the default setting) and no user activity? Would love to learn more if you have any details or links - thank you.
- deleted 2y ago[deleted]
- sp332 2y agohttps://krebsonsecurity.com/2019/05/microsoft-patches-wormable-flaw-in-windows-xp-7-and-windows-2003/ https://krebsonsecurity.com/2019/05/microsoft-patches-wormab... Looks like I misread and this requires RDP to be enabled, which is not the default. But it was pretty common, Rob Graham counted almost one million hosts. https://blog.erratasec.com/2019/05/almost-one-million-vulnerable-to.html https://blog.erratasec.com/2019/05/almost-one-million-vulner...
- miles 2y agoThanks for the kind followup - I was on a bad mobile connection and couldn't dig around.