Microsoft: Patch old Windows systems or risk computer worm

A serious flaw can be exploited to create malware capable of spreading from one vulnerable machine to another.
 By  Michael Kan  for PCMag  on 
Microsoft: Patch old Windows systems or risk computer worm
Credit: Drew Angerer/Getty Images

PCMag.com is a leading authority on technology, delivering Labs-based, independent reviews of the latest products and services. Our expert industry analysis and practical solutions help you make better buying decisions and get more from technology.

Microsoft is trying to prevent the outbreak of a computer worm by urging those running older Windows systems to patch their machines.

Redmond has discovered a serious flaw in Windows 7, Windows XP, and Windows Server 2003 and 2008 systems, which can be exploited to create malware capable of automatically spreading from one vulnerable machine to another.

"While we have observed no exploitation of this vulnerability, it is highly likely that malicious actors will write an exploit for this vulnerability and incorporate it into their malware," Microsoft said.

The vulnerability deals with the Remote Desktop Services function in Windows, which can allow a user to take control of the machine over a network. Enterprises often choose to activate the feature on PCs and servers as a way to control them remotely.

Normally, the access requires a correct username and password. However, Microsoft discovered that an "unauthenticated attacker" can install malware on a Windows machine through the Remote Desktop Services function by sending specially crafted data packets.

"An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights," Microsoft said in its vulnerability advisory.

The bug also requires no interaction from the owner of the affected Windows machine. So theoretically, an attacker could scan the internet to find additional machines to target. An estimated 3 million Remote Desktop Protocol endpoints are currently exposed to the internet, according to security researcher Kevin Beaumont, who cites data from device search engine Shodan.

Fortunately, Windows 10 and Windows 8 are immune from the threat. The attack also won't work on machines with Remote Desktop Services disabled, according to Microsoft. So the problem is probably less of a threat to consumers than to corporations, which tend to manage large fleets of older Windows machines.

However, the newly discovered vulnerability is so serious that Microsoft is warning it could pave the way for another attack similar to WannaCry, which took over hundreds of thousands of Windows PCs across the world in 2017. As a result, the company has issued patches for Windows Server 2003 and XP, which it no longer supports.

Microsoft is also applying the patches to Windows 7 and Windows Server 2008 systems that have automatic updates switched on.

Editor's Note: This story has been updated with comment from Microsoft about how disabling the Remote Desktop Protocol will prevent the threat.

Topics Microsoft

Mashable Potato

Recommended For You


This $45 Microsoft upgrade makes an old PC feel brand new again
The Ultimate Microsoft Office Professional 2021 for Windows: Lifetime License + Windows 11 Pro Bundle


Refresh your computer for $20 with these Microsoft apps
Microsoft Office Professional Plus 2019 for Windows

More in Tech
Amazon's sister site is having a one-day sale, and this Bissell TurboClean deal is too good to skip
A woman using the Bissell TurboClean Cordless Hard Floor Cleaner Mop and Lightweight Wet/Dry Vacuum.

The best smartwatch you've never heard of is on sale for less than $50
Nothing CMF Watch 3 Pro in light green with blue and green abstract background

Reddit r/all takes another step into the grave
Reddit logo on phone screen

Take back your screen from ads and trackers with this $16 tool
AdGuard Family Plan: Lifetime Subscription


Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma

NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.

The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!