If you’re running Windows XP (including Embedded) Windows Server 2003, Server 2003 Datacenter Edition Windows 7 Windows Server 2008, Server 2008 R2 Yo
[See the full post at: Good news: The “wormable” security hole in XP, 7, and related Servers, isn’t being exploited yet]
![]() |
Patch reliability is unclear, but widespread attacks make patching prudent. Go ahead and patch, but watch out for potential problems. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Good news: The “wormable” security hole in XP, 7, and related Servers, isn’t being exploited yet
Home » Forums » Newsletter and Homepage topics » Good news: The “wormable” security hole in XP, 7, and related Servers, isn’t being exploited yet
- This topic has 17 replies, 11 voices, and was last updated 5 years, 11 months ago.
Tags: May 2019 Black Tuesday
AuthorTopicwoody
ManagerMay 16, 2019 at 8:21 am #1638449Viewing 7 reply threadsAuthorReplies-
geekdom
AskWoody_MVPMay 16, 2019 at 8:57 am #1639004I usually serve as beta (guinea) pig for patches. This is one instance, as per instructions, that everyone should serve as beta (guinea) pig.
On permanent hiatus {with backup and coffee}
offline▸ Win10Pro 2004.19041.572 x64 i3-3220 RAM8GB HDD Firefox83.0b3 WindowsDefender
offline▸ Acer TravelMate P215-52 RAM8GB Win11Pro 22H2.22621.1265 x64 i5-10210U SSD Firefox106.0 MicrosoftDefender
online▸ Win11Pro 22H2.22621.1992 x64 i5-9400 RAM16GB HDD Firefox116.0b3 MicrosoftDefender -
TheSuffering
AskWoody Lounger -
woody
ManagerMay 16, 2019 at 12:18 pm #1641199I strongly suggest that you patch preemptively.
When it hits, it’ll hit hard. There are a lot of people working on turning the hole into money.
4 users thanked author for this post.
-
TheSuffering
AskWoody Lounger
-
-
-
anonymous
GuestMay 16, 2019 at 3:52 pm #1642708MDS seems like a bigger problem for ordinary users in my opinion, and much harder to stay safe from.
“Allow remote assistance connections to this computer” is an default setting when you install windows 7 and also windows 10(maybe all microsoft operating systems). This has been an “wormable” for ages or atleast a weakspot for normal users because microsoft has it on as default. The first thing you do after installing the os: Turn off this and block port 3389 in firewall or anything with “Remote” in firewall.
What will even microsoft do with this when you patch with may update, turn of remote asssistance?
The bigger problem and why you should update(and all operating systems) is the Microarchitectural Data Sampling (MDS) or Zombieload, and everyone with an Intel cpu with Hyper-Threading is extra exposed.
- CVE-2018-12126 Microarchitectural Store Buffer Data Sampling (MSBDS)
- CVE-2018-12130 Microarchitectural Fill Buffer Data Sampling (MFBDS)
- CVE-2018-12127 Microarchitectural Load Port Data Sampling (MLPDS)
- CVE-2019-11091 Microarchitectural Data Sampling Uncacheable Memory (MDSUM)
Not that I understand much of this but this seems bad https://youtu.be/Oeb-O4yKK2c
1 user thanked author for this post.
-
GoneToPlaid
AskWoody LoungerMay 16, 2019 at 11:10 pm #1648698 -
satrow
AskWoody MVP
-
-
-
Nibbled To Death By Ducks
AskWoody PlusMay 16, 2019 at 6:43 pm #1645335Ummm…. so this one from yesterday was a “Red Herring” (no pun intended)?
“UPDATE: I’ve now seen one reliable report that there’s an RDP exploit in the wild. The attacks are said to come from China.”
I’m easily confused.
Win7 Pro SP1 64-bit, Dell Latitude E6330 ("The Tank"), Intel CORE i5 "Ivy Bridge", 12GB RAM, Group "0Patch", Multiple Air-Gapped backup drives in different locations. Linux Mint Newbie
--
"The more kinks you put in the plumbing, the easier it is to stop up the pipes." -Scotty -
GoneToPlaid
AskWoody LoungerMay 16, 2019 at 11:01 pm #1648464I went ahead and installed the May security only update KB4499175 on my primary Win7 production machine. Thankfully, it installed cleanly and with no apparent issues so far. Given the potential seriousness of the threat, I figured that I would bite the bullet and run KB4499175 through its paces in a daily production environment.
No known issues are presently listed for the May security only update KB4499175.
Two known issues are presently listed for the May monthly rollup KB4499164. One issue is serious and involves McAfee products. Yeah, more AV issues!
Woody says that all XP, Win7 and related servers should get patched. I agree. Win8 and Win10 users have nothing to worry about.
For Win7 users on Group A and for the time being, you could install the May security only update KB4499175, just for the sake of getting patched against this wormable security hole, since the security only update presently has no known issues. Later and if and when the “all clear” is given for the May monthly rollup KB4499164, one would uninstall KB4499175 and reboot, and then install KB4499164. Or one could wait until June and install the June monthly rollup when that is given the “all clear.” The latter might be preferable since there are issues with IE and Edge in the May monthly rollup KB4499164.
Note that the May security only update KB4499175 also includes the separate pciclearstalecache.exe utility. I can’t remember if one is supposed to run this EXE before or after installing the update since the underlying issue only affects those who run some types of virtual machine software.
Needless to say, hopefully everyone is aware that it is a really good idea to disable remote assistance connections and Remote Desktop. There are alternative products which are far more secure.
2 users thanked author for this post.
-
GoneToPlaid
AskWoody Lounger -
b
AskWoody_MVP
-
-
-
Nibbled To Death By Ducks
AskWoody PlusMay 17, 2019 at 12:03 am #1649658I went ahead and installed the May security only update KB4499175 on my primary Win7 production machine.
Yup, all patched here too with no ill effects…but I did NOT know about RDP, RA and such matters, Networking being my weakest point.
“Ah, the tangled wed we weave, when first we practice to…network?”
Still wondering about that one report Woody posted about a confirmed exploit originating from China…
Win7 Pro SP1 64-bit, Dell Latitude E6330 ("The Tank"), Intel CORE i5 "Ivy Bridge", 12GB RAM, Group "0Patch", Multiple Air-Gapped backup drives in different locations. Linux Mint Newbie
--
"The more kinks you put in the plumbing, the easier it is to stop up the pipes." -Scotty -
woody
ManagerMay 17, 2019 at 10:30 am #1657794Still wondering about that one report Woody posted about a confirmed exploit originating from China…
I was wondering about that, too. My guess is that it’s a case of mistaken identity. The people who watch over such things say there’s nothing (yet) in the wild.
-
-
honx
AskWoody LoungerMay 17, 2019 at 4:49 am #1654665despite defcon 3 for windows 7 i still wait. i remember march 2018, having to roll back to december 2017 patch level because of patch screw ups. i’m not gonna repeat that. i stay put. i wait until there is something exploiting it.
btw. remote desktop services startup type ist set to manual, it isn’t even runnung. so is my computer even at risk without this service running?
PC: Windows 7 Ultimate, 64bit, Group B
Notebook: Windows 8.1, 64bit, Group B -
woody
Manager
-
-
rdgwalker
AskWoody Plus -
Paul T
AskWoody MVPMay 17, 2019 at 9:42 am #1656990The MS downloads don’t list embedded, so you should be OK.
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708cheers, Paul
1 user thanked author for this post.
-
Viewing 7 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Return of the brain dead FF sidebar
by
EricB
13 minutes ago -
windows settings managed by your organization
by
WSDavidO61
1 hour, 10 minutes ago -
Securing Laptop for Trustee Administrattor
by
PeachesP
3 hours, 58 minutes ago -
The local account tax
by
Susan Bradley
3 hours, 10 minutes ago -
Recall is back with KB5055627(OS Build 26100.3915) Preview
by
Alex5723
6 hours, 30 minutes ago -
Digital TV Antenna Recommendation
by
Win7and10
6 hours, 6 minutes ago -
Server 2019 Domain Controllers broken by updates
by
MP Support
18 hours, 23 minutes ago -
Google won’t remove 3rd party cookies in Chrome as promised
by
Alex5723
20 hours, 2 minutes ago -
Microsoft Manager Says macOS Is Better Than Windows 11
by
Alex5723
23 hours, 14 minutes ago -
Outlook (NEW) Getting really Pushy
by
RetiredGeek
1 hour, 39 minutes ago -
Steps to take before updating to 24H2
by
Susan Bradley
1 hour, 9 minutes ago -
Which Web browser is the most secure for 2025?
by
B. Livingston
6 hours, 6 minutes ago -
Replacing Skype
by
Peter Deegan
13 hours, 36 minutes ago -
FileOptimizer — Over 90 tools working together to squish your files
by
Deanna McElveen
17 hours, 5 minutes ago -
Excel Macro — ask for filename to be saved
by
nhsj
1 day, 1 hour ago -
Trying to backup Win 10 computer to iCloud
by
SheltieMom
4 hours, 30 minutes ago -
Windows 11 Insider Preview build 26200.5570 released to DEV
by
joep517
2 days, 23 hours ago -
Windows 11 Insider Preview build 26120.3941 (24H2) released to BETA
by
joep517
3 days ago -
Windows 11 Insider Preview Build 22635.5305 (23H2) released to BETA
by
joep517
3 days, 1 hour ago -
No April cumulative update for Win 11 23H2?
by
Peobody
1 day, 12 hours ago -
AugLoop.All (TEST Augmentation Loop MSIT)
by
LarryK
3 days, 1 hour ago -
Boot Sequence for Dell Optiplex 7070 Tower
by
Serge Carniol
3 days, 16 hours ago -
OTT Upgrade Windows 11 to 24H2 on Unsupported Hardware
by
bbearren
3 days, 20 hours ago -
Inetpub can be tricked
by
Susan Bradley
2 days, 3 hours ago -
How merge Outlook 2016 .pst file w/into newly created Outlook 2024 install .pst?
by
Tex265
2 days, 14 hours ago -
FBI 2024 Internet Crime Report
by
Alex5723
3 days, 23 hours ago -
Perplexity CEO says its browser will track everything users do online
by
Alex5723
1 day, 9 hours ago -
Login issues with Windows Hello
by
CWBillow
4 days, 11 hours ago -
How to get into a manual setup screen in 2024 Outlook classic?
by
Tex265
3 days, 22 hours ago -
Linux : ARMO rootkit “Curing”
by
Alex5723
4 days, 22 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.