HomeSecurityAfter Wanna Cry comes EsteemAudit | Patch for Windows...

After Wanna Cry comes EsteemAudit | Patch for Windows XP

In the wake of WannaCry, security researchers are warning of a second massive wave of cyberattacks, as SMB is not the only vulnerable protocol that can be exploited by attackers for global scale attacks. The Remote Desktop Protocol or RDP (Port 3389) is also proving vulnerable as it can be exploited by hackers with the help of the dangerous EsteemAudit exploit, which is linked to the NSA. All systems running Windows Server 2003 or Windows XP are at risk, with researchers from security firm enSilo now providing a temporary solution to address the threat, with the release of an unofficial patch.

Windows XP - Windows XP

Windows RDP Exploit 'EsteemAudit' Remains Unpatched

Among the hacking tools leaked in recent months by the Shadow Brokers are several exploits that have not been addressed by Microsoft with the release of corresponding updates, such as “EnglishmanDentist”, “EsteemAudit” and “ExplodingCan”.

The availability of these exploits and hacking tools is a serious problem, as they can be exploited by attackers, putting millions of Windows systems around the world at risk.

"Of the three remaining exploits, named EnglishmanDentist, EsteemAudit, and ExplodingCan, none are reproducible on supported platforms, meaning that customers running Windows 7 or later versions of Windows and Exchange 2010 or later versions of Exchange are not at risk," Microsoft says.

But what about older versions of Microsoft's operating system, such as Windows XP?

Let's start from the beginning. EsteemAudit is a hacking tool that targets theRemote Desktop Protocol, or RDP (port 3389) and can infect machines running the unsupported Windows Server 2003 and Windows XP operating systems.

Security researchers Omri Misgav and Tal Liberman, who work for security firm Ensilo and developed an unofficial patch to address EsteemAudit, report:

“Even a single infected machine is enough to put your business at even greater risk. Among the powerful exploits published by the Shadow Brokers group is ESTEEMAUDIT, an RDP exploit that can allow malware to infiltrate an organization in a manner similar to WannaCry.”.

EnSilo is distributing the patch against ESTEEMAUDIT for free, with the aim of helping organizations and individual users around the world improve their security.

It is important to note that patching this exploit will not make Windows XP systems completely secure. There are still many unwanted vulnerabilities in Windows XP and we urge organizations to update their systems.

Until that happens, we believe that dangerous exploits like ESTEEMAUDIT and ETERNALBLUE need to be patched.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS