SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Why a Windows Flaw Patched Nine Days Ago is Still Spooking the Internet
Date    Saturday May 25 2019, @07:10AM
Author    martyb
Topic   
from the maybe-we-*should*-be-worried dept.
https://soylentnews.org/article.pl?sid=19/05/25/0237201

Fnord666 writes:

It has been nine days since Microsoft patched the high-severity vulnerability known as BlueKeep, and yet the dire advisories about its potential to sow worldwide disruptions keep coming.

Until recently, there was little independent corroboration that exploits could spread virally from computer to computer in a way not seen since the WannaCry and NotPetya worms shut down computers worldwide in 2017. Some researchers felt Microsoft has been unusually tight-lipped with partners about this vulnerability, possibly out of concern that any details, despite everyone's best efforts, might hasten the spread of working exploit code.

Until recently, researchers had to take Microsoft's word the vulnerability was severe. Then five researchers from security firm McAfee reported last Tuesday that they were able to exploit the vulnerability and gain remote code execution without any end-user interaction. The post affirmed that CVE-2019-0708, as the vulnerability is indexed, is every bit as critical as Microsoft said it was.

"There is a gray area to responsible disclosure," the researchers wrote. "With our investigation we can confirm that the exploit is working and that it is possible to remotely execute code on a vulnerable system without authentication."

Story:
https://arstechnica.com/information-technology/2019/05/why-a-windows-flaw-patched-nine-days-ago-is-still-spooking-the-internet/

Further Reading:
https://arstechnica.com/information-technology/2019/05/microsoft-warns-wormable-windows-bug-could-lead-to-another-wannacry/

Entry in the "Common Vulnerabilities and Exposures" database: CVE-2019-0708.


Original Submission

Links

  1. "Fnord666" - https://soylentnews.org/~Fnord666/
  2. "patched the high-severity vulnerability known as BlueKeep" - https://arstechnica.com/information-technology/2019/05/microsoft-warns-wormable-windows-bug-could-lead-to-another-wannacry/
  3. "without any end-user interaction" - https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/rdp-stands-for-really-do-patch-understanding-the-wormable-rdp-vulnerability-cve-2019-0708/
  4. "CVE-2019-0708" - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0708
  5. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=33985

© Copyright 2023 - SoylentNews, All Rights Reserved

printed from SoylentNews, Why a Windows Flaw Patched Nine Days Ago is Still Spooking the Internet on 2023-06-16 16:28:16