Running Windows 7, 8 or 10? You need to patch these critical vulnerabilities now

(Image credit: Microsoft)

Microsoft has issued patches for a pair of critical vulnerabilities which are ‘wormable’ and present in all recent versions of Windows, with the software giant advising that you should download these as soon as possible due to the risk involved here.

The vulnerabilities in Remote Desktop Services, which allow for remote code execution – meaning the attacker can pretty much pull off anything, such as installing malware or plundering your data – are codenamed CVE-2019-1181 and CVE-2019-1182.

They affect Windows 7 SP1, Windows 8.1, and all supported versions of Windows 10 (as well as Windows Server 2008 R2 SP1, Windows Server 2012/R2, and Windows 10 server versions).

The fact that they are wormable means that malware built to exploit these security flaws could spread from computer to computer without any user interaction, assuming those PCs are vulnerable of course. And naturally, that’s the most worrying kind of malware, where you don’t have to be tricked into clicking some dodgy link or downloading something with a payload inside.

Microsoft stressed: “It is important that affected systems are patched as quickly as possible because of the elevated risks associated with wormable vulnerabilities like these.”

You can check here to download the security patches manually, but if you have automatic updates switched on, your OS will grab the relevant fixes for you (or you could head to Windows Update, and check for new updates).

Remotely dangerous

If all this is ringing a bell or three, that’s probably because we recently witnessed BlueKeep emerging, another wormable vulnerability in Remote Desktop Services, although that particular flaw didn’t affect Windows 8 or Windows 10.

This time around, all versions of Windows are under threat – except for Windows XP – so you should patch up pronto (and if you’re still on XP, well, that’s a far more worrying state of security affairs in itself).

Microsoft does observe, however, that there is no evidence the vulnerabilities were known to any third-parties before this announcement.

Of course, hackers may have previously found the flaws without Microsoft realizing, and at any rate, now the vulnerabilities have been publicly detailed, there’s an obvious danger of a weaponized exploit turning up – and possibly in quite a rapid timeframe.

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Windows
AOC Agon Pro AG276FK gaming monitor tilted slightly to the side, showing the Windows desktop screen
Windows 11 users get ready for more ‘recommendations’ from Microsoft – but I’m relieved to say these suggestions might actually be useful
Microsoft Store logo on a blurred background
There's finally a fix for an annoying Microsoft Store bug that's older than Windows 11
Portrait of African-American teenage boy studying at home or in college dorm and using laptop, copy space
Windows 11’s Notepad gets AI-powered ‘Rewrite’ feature, but not everyone’s going to be happy about it
Copilot on a laptop
Microsoft quietly updates Copilot to cut down on unauthorized Windows activations
Windows fail
It looks like Microsoft might have broken Windows 11 24H2 again as performance plummets with Intel's latest CPUs
Windows 11 update with Task Manager menu
Microsoft is fixing Windows 11 Task Manager’s quirky reporting of CPU usage, and a much-wanted change for the lock screen is coming, too
Latest in News
Q Acoustics Q SUB80, QSUB100 and QSUB120 subwoofers
Q Acoustics wants to bring the bass to your post-Oscars movie catch-up
Hospital
Major Oracle outage hits US Federal health record systems
Samsung Galaxy A56 display
Samsung’s new budget handsets are getting One UI 7 before the Galaxy S24 Ultra, and I’m as confused as you are
iPad Pro 13-inch 2024 on a table
The OLED iPad Pro is reportedly less popular than expected – and that could mean these changes to Apple's OLED iPad plans
Sam Porter cradles a baby
Death Stranding 2: On the Beach trailer confirms June release date and an even more harrowing post-apocalyptic world
The Ray-Ban Meta Coperni smart glasses
The new Ray-Ban Meta smart glasses design is an expensive disappointment