This month Microsoft have released an update for Windows Remote Desktop to patch a significant vulnerability – the vulnerability allows an attacker to remotely run code on any unpatched machine without any need to log in.

Vulnerabilities

  • Windows Server 2003
  • Windows Server 2008
  • Windows Server 2008 R2
  • Windows XP
  • Windows 7

Implications

An attacker who successfully exploits this vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights.

Given how prevalent remote desktop is, it is highly likely that self propagating malware worms will be released by attackers over the internet directly and as email or webpage based attacks.

This vulnerability has the potential to be weaponized and deployed quickly and is already being compared to Wannacry though at this point this is presumptive / sensationalism, but the danger is very real and hence this out of band communication about the risk. Microsoft have considered this to be such a level of risk that they have created patches for the long unsupported Windows XP / Server 2003.

Recommendations

We recommend deploying the patch to all relevant machines asap, please bear in mind any legacy devices such as point-of-sale, kiosk, building / door control systems. Customers with vulnerability management with us will be notified of any at risk machines.

If you have any questions please feel free to get in touch.

You can see the full Microsoft blog post HERE

Further Insights from Quorum Cyber.

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

Colorado, USA Office

950 S Cherry St Ste 505
Denver, Colorado
USA
80246

Colorado, USA Office

950 S Cherry St Ste 505
Denver, Colorado
USA
80246

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Arizona, USA Office

1300 S Litchfield Rd
110-L, Goodyear
USA
Arizona 85338

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

950 S Cherry St Ste 505
Denver, Colorado
USA
80246

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



COLORADO, USA OFFICE
950 S Cherry St Ste 505
Denver, Colorado
USA
80246


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content