Jump to content

Microsoft warns of 'destructive cyberattacks', issues new Windows XP patches


Recommended Posts

Posted

Sources: ZDNet / The Verge

 

Citing an "elevated risk for destructive cyberattacks," Microsoft today released an assortment of security updates designed to block attacks similar to those responsible for the devastating WannaCry/WannaCrypt ransomware outbreak last month.

 

Today's critical security updates are in addition to the normal Patch Tuesday releases, Microsoft said. They'll be delivered automatically through Windows Update to devices running supported versions, including Windows 10, Windows 8.1, Windows 7, and post-2008 Windows Server releases.

 

But in an unprecedented move, Microsoft announced that it was also making the patches available simultaneously for manual download and installation on unsupported versions, including Windows XP and Windows Server 2003. Both of those operating systems are still deployed by significant numbers of business customers years after their official support lifecycles ended.

 

The new updates can be found in the Microsoft Download Center or, alternatively, in the Update Catalog.

 

In a blog post shared with ZDNet in advance of today's release, Microsoft's Adrienne Hall, General Manager of the Cyber Defense Operations Center, cited an "elevated risk of cyberattacks by government organizations, sometimes referred to as nation-state actors, or other copycat organizations."

 

The announcement noted that the updates were designed to provide "further protection against potential attacks with characteristics similar to WannaCrypt."

 

A Microsoft spokesperson declined to comment when asked whether the company had received warnings of an imminent attack, either from security researchers or government agencies. However, the tone and timing of today's announcement suggests that today's critical updates are much more than a routine precaution.

 

As is company policy, details of the vulnerabilities addressed were not made available until the updates themselves were released. Presumably, though, the fixes are related to flaws in older versions of the Server Message Block (SMB) protocol. Those vulnerabilities affect all versions of Windows and are also targeting Linux servers with a new active exploit.

 

Microsoft issued a “highly unusual” patch for Windows XP last month to help prevent the spread of the massive WannaCry malware. At least 75,000 computers in 99 countries were affected by the malware which encrypts a computer and demands a $300 ransom before unlocking it. Microsoft stopped supporting Windows XP in April 2014, but the software giant is now taking the unprecedented move of including it in the company’s Patch Tuesday round of security updates today.

 

“In reviewing the updates for this month, some vulnerabilities were identified that pose elevated risk of cyberattacks by government organizations, sometimes referred to as nation-state actors, or other copycat organizations,” says Adrienne Hall, general manager of crisis management at Microsoft. “To address this risk, today we are providing additional security updates along with our regular Update Tuesday service. These security updates are being made available to all customers, including those using older versions of Windows.”

 

Microsoft says it is releasing updates for Windows XP, Windows Vista, and all other more recent unsupported and supported versions of Windows due to an “elevated risk” of attacks that are similar to the WannaCry malware. The patches will be made available on Microsoft’s Download Center or Windows Update. Microsoft says this move to release security updates for platforms not in extended support “should not be viewed as a departure from our standard servicing policies,” and that this is an exception based on intelligence that led it to believe government organizations may use these new vulnerabilities to attack Windows systems.

 

Microsoft isn’t explaining who or what has tipped the company off to these potential new attacks. March’s security patches included fixes for hacking tools that were leaked from the NSA, and Microsoft didn’t acknowledge the source of the security flaw reports then either. There has been speculation that The Shadow Brokers, a group that leaked the NSA exploits, tipped Microsoft in advance to the previous exploits. Microsoft also mysteriously delayed its Patch Tuesday release in February by a month in an unprecedented move, blaming a "last minute issue".

 

If you're still running Windows XP then these new patches should be installed immediately, even though Windows XP wasn't as badly affected by the first WannaCry attacks. While almost all WannaCry victims were running Windows 7 without the latest security updates, it's not clear if these new attacks might target Windows XP more aggressively this time around.

  • Thanks 4
Posted
Is it just me or is the documentation page really badly laid out once you click the "find out more link"? Struggling to pick out which update they're actually referring to once you get to that big table of KB numbers :confused:
Posted
Struggling to pick out which update they're actually referring to once you get to that big table of KB numbers :confused:

I think it's MS17-013 since MS17-010 was the one for WannaCry and all of the others are older.

  • Thanks 1
Posted (edited)

Has it come through on WSUS for you? Just did a manual sync and got loads of new Critical \ Security updates for 2008 and above but none for 2003.

 

Looking at the KB number and searching for it the update keeps talking about Server 2008 but is listed as a vulnerability for 2003, confused muchly...

 

https://support.microsoft.com/en-us/help/4012583/ms17-011-and-ms17-013-description-of-the-security-update-for-microsoft

 

Now there's an XP \ 2003 patch for it here...

 

https://www.microsoft.com/en-us/download/details.aspx?id=55460

 

But not appearing in any automated patching which is going to be a right pain

 

EDIT: saw this in the comments section which looks to be the new XP \ 2003 patch KB4024323:

https://www.catalog.update.microsoft.com/Search.aspx?q=KB4024323&ranMID=24542&ranEAID=TnL5HPStwNw&ranSiteID=TnL5HPStwNw-IlRISJSUiu_Af14KSHrHlA&tduid=(0658ac00db57f0b42ded7aa1a850cd74)(256380)(2459594)(TnL5HPStwNw-IlRISJSUiu_Af14KSHrHlA)()

 

Still no sign of it on WSUS though :(

Edited by gshaw
Posted

From Arthur's article above:

 

But in an unprecedented move, Microsoft announced that it was also making the patches available simultaneously for manual download and installation on unsupported versions, including Windows XP and Windows Server 2003. Both of those operating systems are still deployed by significant numbers of business customers years after their official support lifecycles ended.

 

Just import them into WSUS from the Update Catalogue and then you'll be able to deploy them - I don't think they are automatically releasing them to wsus.

  • Thanks 1
Posted
From Arthur's article above:

 

 

 

Just import them into WSUS from the Update Catalogue and then you'll be able to deploy them - I don't think they are automatically releasing them to wsus.

Not that MS will see this but that's a bloody stupid thing to do not releasing them into WSUS by default :mad:

Posted
Not that MS will see this but that's a bloody stupid thing to do not releasing them into WSUS by default :mad:

 

I think its brave of microsoft to release the updates at all, this could open a pandoras box of what will be updated on future versions past end of life..

Posted
Not that MS will see this but that's a bloody stupid thing to do not releasing them into WSUS by default :mad:

 

Not intending to start a flame war, but I'd say it's only equally as stupid/risky as running a production Server 2003 install still.

 

They must have had some pretty firm information coming in to take this step - it doesn't suit them to prolong XP/2003's life any more but conversely not patching a potential outbreak on the millions of PCs still running these OSs could be devastating. I wonder how many of those running either OS still actively patch and update them anyway?

Posted
Not intending to start a flame war, but I'd say it's only equally as stupid/risky as running a production Server 2003 install still.

 

They must have had some pretty firm information coming in to take this step - it doesn't suit them to prolong XP/2003's life any more but conversely not patching a potential outbreak on the millions of PCs still running these OSs could be devastating. I wonder how many of those running either OS still actively patch and update them anyway?

As per the NHS story sometimes left with little choice due to legacy products with no budget for replacement. In an ideal world anything pre-2012 R2 would be wiped off the face of the computing landscape but we don't live in an ideal world.

 

Just seems bizarre for MS to go to the effort of releasing the patch (and open the Pandora's box mentioned above) but then have systems miss it by not including by default in automated patch regimes.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...