Patches to Wormable Vulnerabilities Issued by Microsoft, ADVANCED clients covered

Environment safety is important to us here at ADVANCED.
As such, we continue to stay up-to-date with the latest security flaws.

Microsoft has released updates for the Remote Desktop Services that include fixing two critical vulnerabilities (CVE-2019-1181 and CVE-2019-1182), which if exploited lead to an attacker taking full control of an affected system. They have stressed the importance of installing patches to address these vulnerabilities as soon as possible. According to Microsoft, like the BlueKeep Vulnerability, these security flaws are “wormable,” meaning it could spread without user interaction throughout the internet and other vulnerable devices.

The following versions of Windows are affected:

Windows 7, 8.1, 10

Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016, and 2019
.

According to Microsoft, at least two of these vulnerabilities (CVE-2019-1181 and CVE-2019-1182) “can be considered ‘wormable’ and [can be equated] to BlueKeep,” referring to a dangerous bug patched earlier this year that Microsoft warned could be used to spread another WannaCry-like ransomware outbreak. “It is highly likely that at least one of these vulnerabilities will be quickly weaponized, and patching should be prioritized for all Windows systems.”

If your workstations are subscribed to a ProACT plan, we will be pushing out these critical updates tonight. Otherwise, we recommend that you take appropriate action and update your systems as soon as possible including your personal devices. We are available to provide assistance to help resolve this issue.

New to ADVANCED? Contact us today to learn how we can help build/protect your company IT environment!

Recent Posts

Security Digest (June 2024)

July 2024 Patch Tuesday – 6/11 Deep Dive: CVSS Breakdown On Critical Vulnerability Vendor Patch Advisories Apple Updates TeamViewer Compromise Snowflake Breach Snowballs As always, Advanced

Read More »

Security Digest (May 2024)

May 2024 Patch Tuesday – 5/14 Threat Grading Overview Vendor Patch Advisories Threat Breakdown: The Return of Revenge Remote Access Trojan Looking Back: WannaCry –

Read More »

Cybersecurity Triad

New cyber threats are emerging every day, keeping us on our toes. Let’s talk about some of these threats, including credential stuffing, password spraying, and

Read More »

Security Digest (April 2024)

April 2024 Patch Tuesday – 4/9 Threat Grading Overview Deep Dive: CVE-2024-26234 and Digital Signatures – Who Can We Trust? Vendor Patch Advisories Emerging Threat:

Read More »

Categories