It's not too often Microsoft tells customers to hurry up and install a patch, which means this must be a bad exploit.
Microsoft usually lets its customers install Patch Tuesday fixes at their own rate, but it’s making a rare exception this week and urging users to hurry up with one severe fix released this past Tuesday.
All told, Microsoft released six security bulletins fixing seven vulnerabilities in Windows, DNS server, Expression Design and Visual Studio. In a separate blog post, Microsoft stressed that one bulletin, MS12-020, should be downloaded and installed by Windows XP, Vista and 7 users right away.
RELATED: Microsoft incites madness with March’s Patch Tuesday release
There are vulnerabilities in this bulletin, both in the Remote Desktop Protocol (RDP). The more severe of these vulnerabilities could allow remote code execution if an attacker sends a sequence of specially-crafted RDP packets to an affected system.
By default, the Remote Desktop Protocol is not enabled on a Windows machine. Systems that do not have RDP enabled are not at risk. That said, Microsoft has rated this bulletin critical and is urging administrators to apply the fix immediately.
“Due to the attractiveness of this vulnerability to attackers, we anticipate that an exploit for code execution will be developed in the next 30 days,” the company wrote in a TechNet blog post.
The exploit, once developed, would succeed even without valid network credentials and give attackers full, unfettered use of the system. They could install or remove programs, view, change or delete data, and create new accounts with full user rights. So, it’s clear why Microsoft is pressing people to install it.
There is some defense, at least, if the patch cannot be immediately installed. First and easiest is to turn off RDP. If it must be used, Microsoft said Windows Vista and Windows 7 systems can enable the RDP’s Network Level Authentication (NLA) to require authentication before a remote desktop session is established. The exploit is still there but NLA would require an attacker to first authenticate to the server before attempting to exploit the vulnerability.
Still, if Microsoft is concerned about it, you should be, too.




