Software
Microsoft Urges Businesses to Patch 'BlueKeep' Flaw
Reported by darkreading.com
Microsoft’s Security Response Team (MSRC) is warning organizations to patch BlueKeep (CVE-2019-0708), a critical remote code execution vulnerability it fixed earlier this month. The flaw is in Remote Desktop Services (RDS), formerly known as Terminal Services, and affects some older versions of Windows. It’s pre-authentication and requires no user interaction; future malware that successfully exploits the bug could spread across vulnerable machines. Fearing this, Microsoft took the unusual step of issuing fixes for out-of-support systems Windows 2003 and XP, and still-supported Windows 7, Server 2008, and Server 2008 R2.