Skip to main content

Older versions of Windows have critical vulnerability, should be updated ASAP

Image used with permission by copyright holder

If you’re running an older version of Windows, it’s vital to update it as soon as possible. Microsoft has warned about a critical security issue called BlueKeep which makes older Windows machines vulnerable to malware.

The vulnerability is technically known as CVE-2019-0708, and is found in Remote Desktop Services. It is a particular concern because the vulnerability is “wormable,” meaning that if a computer is infected through this vulnerability, it can pass on the malware to other computers. This is what allowed the WannaCry malware to spread so quickly and so far in 2017.

Recommended Videos

The vulnerable systems include those running Windows 7, Windows Server 2008 R2, and Windows Server 2008. If, for some unknown reason, you are running an even older version of Windows, like Windows 2003 or Windows XP, then your system is vulnerable too. (And now is a good time to remind you that you really ought to update to Windows 10.)

Please enable Javascript to view this content

If you are running Windows 8 or Windows 10 then you needn’t worry, as the vulnerability won’t affect you.

If you’re wondering how many people are still running these old versions of Windows, you’d be surprised. Microsoft shared a recent report which estimates that nearly one million internet-connected computers are vulnerable, and there could be many more vulnerable computers on corporate networks as well.

“It only takes one vulnerable computer connected to the internet to provide a potential gateway into these corporate networks, where advanced malware could spread, infecting computers across the enterprise,” Simon Pope, Director of Incident Response at Microsoft Security Response Center wrote in a blog post. “This scenario could be even worse for those who have not kept their internal systems updated with the latest fixes, as any future malware may also attempt further exploitation of vulnerabilities that have already been fixed.”

The fix for the vulnerability was released on May 14, so users may not have updated yet. And although Microsoft says they have not yet detected a worm making use of this vulnerability, there is still a considerable risk that one could appear.

To further encourage users to update, Microsoft pointed out that two months passed between the release of a fix for the EternalBlue vulnerability and the time at which WannaCry and other ransomware attacks using it began. That attack caused chaos around the world, so it’s a good reminder of the importance of regularly updating your OS.

Georgina Torbet
Georgina has been the space writer at Digital Trends space writer for six years, covering human space exploration, planetary…
Update your Chrome browser now to gain this critical security feature
Google Chrome icon in mac dock.

Yesterday, in a blog post on Google's security blog, Willian Harris from Chrome's Security Team said that Google is improving the security of Chrome cookies on Windows PCs by adopting a similar method used in macOS to help protect users from info-stealing malware.

The security update addresses session cookies that authenticate your identity when you switch apps without logging back in. Google wants to adopt the security system used by Keychain on macOS and start using "a new protection on Windows," which updates Data Protection API (DPAPI) and brings a new security tool called "application-bound" encryption.

Read more
The best free PC driver update tools everyone should have
Acer Predator XB3 Gaming Monitor review

Updating your drivers is something that's easy to forget, but can you really trust driver update tools? There are a lot of scammy, spammy, nefarious apps out there that promise to update drivers, but are bloatware at best and malware at worst. While here at Digital Trends we might be big fans of doing it the manual way for added control, there are some free PC driver update tools you can use that aren't going to steal your data.

Here are some of our favorite free Windows 11 PC driver update tools that you can trust to do the job they claim.
Intel Driver and Support Assistant

Read more
If you use a VPN, don’t skip this important Windows 11 update
Microsoft Surface Laptop Go 3 rear view showing lid and logo.

It's not you; Windows is causing the issues this time. If the VPN on your Windows 11 or Windows 10 computer is having a hard time connecting, it is likely because of Microsoft's April security updates for Windows 11 (KB5036893 for) and Windows 10 (KB5036892), which have been reported to be the cause of the problems.

But there's good news. According to Microsoft, a patch is now available to fix the VPN problems users are experiencing.

Read more