Last Windows 7 patch updates critical remote desktop flaw
Summary
The NSA also reported that it had found a remote desktop vulnerability, CVE-2020-0611, which affects Windows 7 and newer operating systems, for which Microsoft has also issued a patch. However, since the patches are now publicly released, the underlying vulnerabilities can be reverse-engineered to create exploits that target unpatched systems, it warned. Along with patching the operating system, IT security company Symantec urged IT departments to limit access rights for all software. “To reduce the impact of latent vulnerabilities, always run non-administrative software as an unprivileged user with minimal access rights,” it said. Medical devices are the weakest link – they are not designed with security in mind, have extensive lifecycles and often cannot afford any downtime,” said Leon Lerman, Cynerio’s CEO and co-founder.