Skip to content
The Cyber Security Place

Software

Microsoft Urges Businesses to Patch 'BlueKeep' Flaw

Reported by darkreading.com

Microsoft’s Security Response Team (MSRC) is warning organizations to patch BlueKeep (CVE-2019-0708), a critical remote code execution vulnerability it fixed earlier this month. The flaw is in Remote Desktop Services (RDS), formerly known as Terminal Services, and affects some older versions of Windows. It’s pre-authentication and requires no user interaction; future malware that successfully exploits the bug could spread across vulnerable machines. Fearing this, Microsoft took the unusual step of issuing fixes for out-of-support systems Windows 2003 and XP, and still-supported Windows 7, Server 2008, and Server 2008 R2.

Read the full article at darkreading.com