Microsoft patches expired Windows XP again as fresh exploits emerge

Redmond updates old OS to respond to Shadow Brokers' latest leak

Microsoft has taken the extraordinary step of pushing out an emergency patch for its outdated Windows XP operating system for the second time in a matter of weeks, this time following the release of a host of NSA exploits.

As part of June's Patch Tuesday, the company took the unusual step of issuing more fixes for XP, which went out of support in 2014, in anticipation of more WannaCry-style attacks against the platform - it patched XP'sWannaCryvulnerability some weeks ago.

Advertisement - Article continues below

TheShadow Brokers groupreleased the three exploits that prompted Microsoft to patch its ancient OS. The flaws areconsidered to pose an "elevated risk of cyber attacks by government organisations", Microsoft warned in ablog post.

"Due to the elevated risk for destructive cyber attacks at this time, we made the decision to take this action because applying these updates provides further protection against potential attacks with characteristics similar to WannaCrypt," said Adrienne Hall, general manager for Microsoft's cyber defence operations centre.

Microsoft received criticism for its response to the WannaCry ransomware attack, as Windows XP, which still retains almost 6% of theoperating system market share, was patched much later than Windows 7, 8.1 and 10. Microsoft has said that the latest security patch will be available to all users, including those running outdated operating systems.

Advertisement
Advertisement - Article continues below

Thethree exploits, known as "EnglishmanDentist", "EsteemAudit" and "ExplodingCan" are all classed as remote execution vulnerabilities, allowing hackers to gain access with full user rights. EsteemAudit (CVE-2017-0176) exploits a flaw in the Windows remote code execution protocol, while EnglishmanDentist allows the execution of malware through Windows OLE.

Advertisement - Article continues below

This update is in addition to the regular Patch Tuesday, and while those with automatic updates enabled on Windows 7 or later will receive the patches immediately, those on older systems such as Windows Vista and XP will need to manually update their systems through the Microsoft Download Centre.

"Our decision today to release these security updates for platforms not in extended support should not be viewed as a departure from our standard servicing policies," said Eric Doerr, general manager at Microsoft's security response centre. "Based on an assessment of the current threat landscape by our security engineers, we made the decision to make updates available more broadly."

Advertisement

Recommended

Visit/security/vulnerability/355236/hp-support-assistant-flaws-leave-windows-devices-open-to-attack
vulnerability

HP Support Assistant flaws leave Windows devices open to attack

6 Apr 2020
Visit/security/cyber-security/355234/safari-bug-let-hackers-access-cameras-on-iphones-and-macs
cyber security

Safari bug let hackers access cameras on iPhones and Macs

6 Apr 2020
Visit/business/business-operations/355230/skype-launches-meet-now-calls-which-dont-require-sign-up-or
video conferencing

Skype takes on Zoom with 'Meet Now' video calling feature

6 Apr 2020
Visit/software/video-conferencing/355229/zoom-we-moved-too-fast
video conferencing

Zoom CEO admits company "moved too fast" as privacy issues mount

6 Apr 2020

Most Popular

Visit/development/application-programming-interface-api/355192/apple-buys-dark-sky-weather-app-and-leaves
application programming interface (API)

Apple buys Dark Sky weather app and leaves Android users in the cold

1 Apr 2020
Visit/data-insights/data-management/355170/oracle-cloud-courses-are-free-during-coronavirus-lockdown
data management

Oracle cloud courses are free during coronavirus lockdown

31 Mar 2020
Visit/security/privacy/355211/google-releases-location-data-to-showcase-effectiveness-of-coronavirus
privacy

Google releases location data to show effectiveness of coronavirus lockdowns

3 Apr 2020