• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Microsoft Fixes Critical RDP Security Hole, Asks Users to Patch or Risk Attacks

btarunr

Editor & Senior Moderator
Staff member
Joined
Oct 9, 2007
Messages
47,670 (7.43/day)
Location
Dublin, Ireland
System Name RBMK-1000
Processor AMD Ryzen 7 5700G
Motherboard Gigabyte B550 AORUS Elite V2
Cooling DeepCool Gammax L240 V2
Memory 2x 16GB DDR4-3200
Video Card(s) Galax RTX 4070 Ti EX
Storage Samsung 990 1TB
Display(s) BenQ 1440p 60 Hz 27-inch
Case Corsair Carbide 100R
Audio Device(s) ASUS SupremeFX S1220A
Power Supply Cooler Master MWE Gold 650W
Mouse ASUS ROG Strix Impact
Keyboard Gamdias Hermes E2
Software Windows 11 Pro
Among its usual chunk of updates for Windows, Office, and other products covered by Microsoft Update, Redmond released a key security update for the Remote Desktop Protocol (2671387), and asked all users to apply it as soon as possible. It asked system administrators to give the patch "special priority," given the severity of the security hole. The security hole with RDP spans across all versions of Windows, across all machine architectures. The security hole allows hackers to gain access to RDP hosts and clients. Microsoft gives it 30 days before hackers can develop malware that can exploit the security hole. Find out more about the security hole, and its patch here.



View at TechPowerUp Main Site
 
I'm not using it but then again i install latest updates as soon as they become available.
 
Microsoft needs to figure out how to install updates without requiring a restart. I had to restart my server to install this and another updates. :(
 
Well I don't use RDP, have it disabled, but to be safe I will still install this update.
 
Microsoft needs to figure out how to install updates without requiring a restart. I had to restart my server to install this and another updates. :(

If you update code related to services then those services will need to be restarted to utilize the new code. Or apparently in this case to be secured. Don't really see any way around that, though I'm no software developer.
 
If you update code related to services then those services will need to be restarted to utilize the new code. Or apparently in this case to be secured. Don't really see any way around that, though I'm no software developer.

Actually, that is the solution :)

If Windows Update could automatically stop>update>start services, then many full system restarts wouldn't be necessary.

I know some people who've done this manually to minimize downtime and/or have a remarkable up time.
 
Microsoft needs to figure out how to install updates without requiring a restart. I had to restart my server to install this and another updates. :(

Actually, that is the solution :)

If Windows Update could automatically stop>update>start services, then many full system restarts wouldn't be necessary.

I know some people who've done this manually to minimize downtime and/or have a remarkable up time.

oh yeah, just ad a crazy morning,. having to restart 4 servers here, and when you do that you have the phone ringing non stop ... lots of fun

we really need a restart less windows server... like the linux server.... this is driving me crazy considering that each windows server have like 6 vm runing on each ..... its a pain!
 
Got it. Windows always updates for me automatically! And I also have this turned off. No need for it.
 
I knew anything related to remote registry/desktop is a major threat. These services should only be used if youre behind a hardware firewall/proxy/intranet/ethernet.
 
Microsoft needs to figure out how to install updates without requiring a restart. I had to restart my server to install this and another updates. :(

Indeed, if it is possible with Linux then why not with Windows? Only if the kernel will get modified by the updates/new drivers, a restart should be necessary.

Silly Windows...
 
oh yeah, just ad a crazy morning,. having to restart 4 servers here, and when you do that you have the phone ringing non stop ... lots of fun


That's why you restart them after hours, if at all possible. Last thing I want is the owner coming to me saying his email isn't working while I wait 30 minutes for our SBS 08 server to restart. :shadedshu


As with others I don't understand why no restarting is required in Linux while it is required in Windows?
 
have to remote connect to our office server to patch RDP, irony :laugh:
 
have to remote connect to our office server to patch RDP, irony :laugh:

Yeah, I had to RDP into my servers to apply the patch as well.:roll:
 
Back
Top