
Microsoft has been forced to deal with its old operating system, Windows XP, rather belatedly. The company has stopped officially updating this version of Windows. However, recently, the National Security Agency ( NSA ) began warning users who are still using Windows XP to manually update their systems to protect themselves from cybercrime, due to a newly discovered bug.
The advisory note issued by the NSA reads as follows:
“The National Security Agency urges Microsoft Windows administrators and users to ensure they are running an up-to-date system against growing threats. Recent warnings from Microsoft have highlighted the importance of installing patches to address a protocol vulnerability in older versions of Windows. Microsoft has warned that this flaw is potentially “wormable,” meaning it could spread without user interaction over the Internet. We have seen devastating worms wreak havoc on unpatched systems with widespread impact, and we are seeking to encourage increased protection against this flaw.
CVE-2019-0708, also known as 'BlueKeep,' is a vulnerability in the Remote Desktop Protocol (RDP). It occurs in Windows 7, Windows XP, Server 2003, and 2008, and although Microsoft has issued a patch, potentially millions of machines are still vulnerable.
This is the type of vulnerability that malicious actors exploit by using software code that specifically targets the vulnerability. For example, the vulnerability could be exploited to conduct denial of service attacks. It is likely only a matter of time before remote exploit code for this vulnerability becomes widely available. The NSA is concerned that malicious actors will use the vulnerability in ransomware and exploit kits that contain other known vulnerabilities, increasing the potential for exploiting other unpatched systems.”.
