The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    URGENT! Anyone with Windows Professional Must READ : MS12-020 CRITICAL

    Discussion in 'Windows OS and Software' started by BlakeRoss, Mar 15, 2012.

  1. BlakeRoss

    BlakeRoss Notebook Consultant

    Reputations:
    0
    Messages:
    218
    Likes Received:
    0
    Trophy Points:
    30
    Microsoft yesterday released a level 1 critical patch yesterday for the MS12-020 exploit. If you have Windows Professional with or without Remote Desktop enabled, you must immediately apply patch KB2621440 and/or KB2667402.

    (see Microsoft Security Bulletin MS12-020 - Critical : Vulnerabilities in Remote Desktop Could Allow Remote Code Execution (2671387) for details)

    This is the most serious exploit in a very long time, it allows any programmer the ability to compromise any RDC enabled windows machine. This will launch a wave of worms and viruses across the globe imminently, and leave sensitive corporate, government, and personal computers COMPLETELY OPEN to anyone with a working knowledge of this exploit.

    Patch this NOW
     
    Last edited by a moderator: May 8, 2015
  2. BlakeRoss

    BlakeRoss Notebook Consultant

    Reputations:
    0
    Messages:
    218
    Likes Received:
    0
    Trophy Points:
    30
    This also includes all Windows Server operating systems
     
  3. Pirx

    Pirx Notebook Virtuoso

    Reputations:
    3,001
    Messages:
    3,005
    Likes Received:
    416
    Trophy Points:
    151
    This is part of the set of patches distributed with Windows Update on Tuesday. No need to get over-excited. Everyone who has let Windows Update run its course will have this installed by now.
     
  4. BlakeRoss

    BlakeRoss Notebook Consultant

    Reputations:
    0
    Messages:
    218
    Likes Received:
    0
    Trophy Points:
    30
    Agree that for individuals and organizations with good security policies, windows updates will be configured to automatically download and install critical patches. But in my experience this is not the case for a very sizable portion of the Windows OS community. Many have automatic update disabled, or set to download but install only on prompt.

    Just realize that anyone with remote desktop access enabled (regardless of port) can now be controlled in a matter of seconds by anyone who has working knowledge of this exploit. Get ready for the avalanche of problems that are going to be reported in the media when all these web servers and sensitive government computers get broken into