Categories: PCSecurityWorkspace

Microsoft Warns Of Attractive Remote Desktop Flaw

Microsoft has urged customers to patch a critical vulnerability affecting its Remote Desktop software, warning the flaw will catch the attention of cyber criminals.

This week’s Patch Tuesday was a small one of just six bulletins, yet the MS12-020 vulnerability has caused some panic as it allows for remote code execution, although Microsoft said it is not aware of any attacks in the wild.

Time to panic?

The flaw affects a specific subset of systems – those running the Remote Desktop Protocol (RDP). The fact that the RDP is disabled by default may help allay fears somewhat, as it means most systems will not be affected.

“However, due to the attractiveness of this vulnerability to attackers, we anticipate that an exploit for code execution will be developed in the next 30 days,” Microsoft said in its blog post. “This issue is potentially reachable over the network by an attacker before authentication is required. RDP is commonly allowed through firewalls due to its utility.

“During our investigation, we determined that this vulnerability is directly exploitable for code execution. Developing a working exploit will not be trivial – we would be surprised to see one developed in the next few days.”

Companies that run Remote Desktop have been advised to enable Network Level Authentication (NLA). This function would require an attacker to authenticate to the server before attempting to exploit the flaw, mitigating the threat significantly.

“We urge you to promptly apply this security update. We also encourage you to consider how you might harden your environment against unauthenticated, attacker-initiated RDP connections,” Microsoft added.

If concerned, head to Microsoft’s advisory on the vulnerability.

This month’s Patch Tuesday also included one moderate and four important security bulletins.

How well do you know your operating systems? Take our quiz

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Programmer Sentenced To Five Years In Prison For Bitcoin Laundering

Ilya Lichtenstein sentenced to five years in prison for hacking into a virtual currency exchange…

26 mins ago

Hate Speech Watchdog CCDH To Quit Musk’s X

Target for Elon Musk's lawsuit, hate speech watchdog CCDH, announces its decision to quit X…

17 hours ago

Meta Fined €798m Over Alleged Facebook Marketplace Violations

Antitrust penalty. European Commission fines Meta a hefty €798m ($843m) for tying Facebook Marketplace to…

19 hours ago

Elon Musk Rebuked By Italian President Over Migration Tweets

Elon Musk continues to provoke the ire of various leaders around the world with his…

20 hours ago

VW, Rivian Launch Joint Venture, As Investment Rises To $5.8 Billion

Volkswagen and Rivian officially launch their joint venture, as German car giant ups investment to…

21 hours ago

AMD Axes 4 Percent Of Staff, Amid AI Chip Focus

Merry Christmas staff. AMD hands marching orders to 1,000 employees in the led up to…

24 hours ago