Yes, new updates for Windows XP and Windows Server 2003: Microsoft has confirmed that its latest round of security updates fixes three remaining vulnerabilities created by the NSA (US National Security Agency), which the company had previously said it would not patch.
The company confirmed the release of patches for the exploits, which only affected older operating systems Windows XP and Windows Server 2003.
The release comes as the company appears to have realized the "increased risk of catastrophic cyberattacks" following last month's ransomware cyberattack.
Microsoft updated all supported versions of Windows with the April updates, except for three that only affected older versions of Windows and that users had to upgrade.
But after the spread of WannaCry last month, which locked thousands of computers, Microsoft decided to fix the remaining security gaps to avoid a similar incident.
A company spokesperson said the three Windows exploits – dubbed ENGLISHMANDENTIST, ESTEEMAUDIT and EXPLODINGCAN – have been fixed in the June security updates.
"These vulnerabilities are quite serious and continue to circulate, even if the affected systems remain down for some time," said Sean Dillon, senior security analyst at RiskSense, in an email to ZDNet.
“The biggest threat is not necessarily ransomware. The installation of hidden malware, such as bank account-stealing software, spyware and key-loggers, as well as software that allows the leakage of classified information, pose a huge risk if an attacker is able to compromise an internal network and install backdoors,” he added.
Microsoft, on the other hand, told ZDNet that the decision to fix these flaws was a "rare move," adding that it "should not be considered a deviation from the company's standard service policies.".
