Running Windows 7, 8 or 10? You need to patch these critical vulnerabilities now

(Image credit: Microsoft)

Microsoft has issued patches for a pair of critical vulnerabilities which are ‘wormable’ and present in all recent versions of Windows, with the software giant advising that you should download these as soon as possible due to the risk involved here.

The vulnerabilities in Remote Desktop Services, which allow for remote code execution – meaning the attacker can pretty much pull off anything, such as installing malware or plundering your data – are codenamed CVE-2019-1181 and CVE-2019-1182.

They affect Windows 7 SP1, Windows 8.1, and all supported versions of Windows 10 (as well as Windows Server 2008 R2 SP1, Windows Server 2012/R2, and Windows 10 server versions).

The fact that they are wormable means that malware built to exploit these security flaws could spread from computer to computer without any user interaction, assuming those PCs are vulnerable of course. And naturally, that’s the most worrying kind of malware, where you don’t have to be tricked into clicking some dodgy link or downloading something with a payload inside.

Microsoft stressed: “It is important that affected systems are patched as quickly as possible because of the elevated risks associated with wormable vulnerabilities like these.”

You can check here to download the security patches manually, but if you have automatic updates switched on, your OS will grab the relevant fixes for you (or you could head to Windows Update, and check for new updates).

Remotely dangerous

If all this is ringing a bell or three, that’s probably because we recently witnessed BlueKeep emerging, another wormable vulnerability in Remote Desktop Services, although that particular flaw didn’t affect Windows 8 or Windows 10.

This time around, all versions of Windows are under threat – except for Windows XP – so you should patch up pronto (and if you’re still on XP, well, that’s a far more worrying state of security affairs in itself).

Microsoft does observe, however, that there is no evidence the vulnerabilities were known to any third-parties before this announcement.

Of course, hackers may have previously found the flaws without Microsoft realizing, and at any rate, now the vulnerabilities have been publicly detailed, there’s an obvious danger of a weaponized exploit turning up – and possibly in quite a rapid timeframe.

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Windows
Student sat at a desk with a laptop in a dormitory looking at a mobile phone
Windows 11 could eventually help you understand how fast your PC is - as well as offer tips for making your PC or laptop faster for free
Windows 10
Microsoft gets into the spam game by again emailing Windows 10 users to prod them to upgrade to Windows 11 – is the nagging going too far now?
Using Zipped files and folders in Windows 11
Hidden clues suggest Microsoft is moving another part of Windows 11’s Control Panel to the Settings app – and this time it’s mouse options
A woman sitting in a chair looking at a Windows 11 laptop
Microsoft is supercharging Windows 11’s voice commands on Copilot+ PCs with Snapdragon CPUs, and fine-tuning a few Recall features
A man getting angry with his laptop.
Windows 11 bug deletes Copilot from the OS – is this the first glitch ever some users will be happy to encounter?
Printer
No, your printer isn't possessed: a Windows 11 23H2 bug could be making it print random characters when connected via USB
Latest in News
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedlyleft users exposed for months
Google Pixel 9a
Google is delaying the Pixel 9a to fix a mystery “component quality issue”
The bottom left corner of an Android phone, showing the Phone, Messages, Google icons and Google Search bar
Google Messages remote delete will soon save you from texting embarrassment – and here's how it works
ExpressVPN mobile app and Aircove
ExpressVPN ‘reduces workforce’ for the second time in two years
The Nanoleaf PC Screen Mirror Lightstrip being used on a desktop computer.
Mac gaming could get an intriguing boost – but not in the way you'd expect
Snapdragon G Series
Qualcomm poised to muscle in on AMD's territory with powerful gaming handheld processors