PATCH WATCH By Susan Bradley We’re starting the Windows 7 extended-support era … with more than our fair share of confusion. Before I shed some
[See the full post at: The trials and tribulations of Windows 7]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
The trials and tribulations of Windows 7
Home » Forums » Newsletter and Homepage topics » The trials and tribulations of Windows 7
- This topic has 4 replies, 4 voices, and was last updated 5 years, 3 months ago.
AuthorTopicTracey Capen
AskWoody MVPFebruary 17, 2020 at 1:10 am #2141832Viewing 0 reply threadsAuthorReplies-
AlexEiffel
AskWoody_MVPFebruary 17, 2020 at 10:49 am #2141995Susan,
Thank you for your risk assessment report about Windows 7 post support-era.
About CVE-2020-0738, does it mean that you could get infected while browsing a web page on any browser? If so, it puts the risk at a whole different level than just having to avoid using IE.
Do you have any mitigation to suggest that doesn’t involve patches?
The way I see it, there is a very different category of risk using a PC where you need to download a malicious file and execute it to be infected vs just browsing the web and your browser displaying a tainted ad that will infect you without any other intervention.
A lot of people that consider themselves careful with computers might want to still run Windows 7 with a third-party browser for casual browsing and/or gaming and with nothing of much value on the PC they run it on, but I think it is important they have a good idea of the risk they get exposed.
Distinguishing between the different categories of risk and with the knowledge that it is exploited or not seem important.
-
Cybertooth
AskWoody PlusFebruary 17, 2020 at 11:36 am #2142028A reading of the NVD report for this vulnerability suggests that it’s the type of exploit that is typically delivered via a phishing e-mail or some other method that requires a specific action by a victim who has been targeted as a result of who they are or whom they work for. In other words, it’s highly unlikely that a random user will chance on this exploit merely by surfing the Web. Things would be different, though, if you are an employee of a large company, or of government.
Note that the exploitability score is 2.8 on a scale of 10. While no privileges are needed to take advantage of the flaw, it does require user interaction; see the Base Score Metrics for this value and hover the mouse pointer over “Required”.
-
Susan Bradley
ManagerFebruary 17, 2020 at 11:03 pm #2151324I would recommend “casual browsing” on your phone rather than an unpatched Windows 7. Clicking on something one shouldn’t is too easy these days.
Susan Bradley Patch Lady/Prudent patcher
1 user thanked author for this post.
-
Susan Bradley
Manager
-
-
Viewing 0 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Cox Communications and Charter Communications to merge
by
not so anon
4 hours, 28 minutes ago -
Help with WD usb driver on Windows 11
by
Tex265
3 hours, 36 minutes ago -
hibernate activation
by
e_belmont
7 hours, 21 minutes ago -
Red Hat Enterprise Linux 10 with AI assistant
by
Alex5723
11 hours, 9 minutes ago -
Windows 11 Insider Preview build 26200.5603 released to DEV
by
joep517
14 hours, 14 minutes ago -
Windows 11 Insider Preview build 26120.4151 (24H2) released to BETA
by
joep517
14 hours, 15 minutes ago -
Fixing Windows 24H2 failed KB5058411 install
by
Alex5723
17 hours, 25 minutes ago -
Out of band for Windows 10
by
Susan Bradley
18 hours, 59 minutes ago -
Giving UniGetUi a test run.
by
RetiredGeek
1 day, 1 hour ago -
Windows 11 Insider Preview Build 26100.4188 (24H2) released to Release Preview
by
joep517
1 day, 9 hours ago -
Microsoft is now putting quantum encryption in Windows builds
by
Alex5723
1 day, 7 hours ago -
Auto Time Zone Adjustment
by
wadeer
1 day, 14 hours ago -
To download Win 11 Pro 23H2 ISO.
by
Eddieloh
1 day, 11 hours ago -
Manage your browsing experience with Edge
by
Mary Branscombe
16 hours, 18 minutes ago -
Fewer vulnerabilities, larger updates
by
Susan Bradley
4 hours, 43 minutes ago -
Hobbies — There’s free software for that!
by
Deanna McElveen
11 hours, 8 minutes ago -
Apps included with macOS
by
Will Fastie
8 hours, 59 minutes ago -
Xfinity home internet
by
MrJimPhelps
5 hours, 47 minutes ago -
Convert PowerPoint presentation to Impress
by
RetiredGeek
1 day, 7 hours ago -
Debian 12.11 released
by
Alex5723
2 days, 11 hours ago -
Microsoft: Troubleshoot problems updating Windows
by
Alex5723
2 days, 14 hours ago -
Woman Files for Divorce After ChatGPT “Reads” Husband’s Coffee Cup
by
Alex5723
1 day, 18 hours ago -
Moving fwd, Win 11 Pro,, which is best? Lenovo refurb
by
Deo
25 minutes ago -
DBOS Advanced Network Analysis
by
Kathy Stevens
3 days, 7 hours ago -
Microsoft Edge Launching Automatically?
by
healeyinpa
2 days, 22 hours ago -
Google Chrome to block admin-level browser launches for better security
by
Alex5723
19 hours, 54 minutes ago -
iPhone SE2 Stolen Device Protection
by
Rick Corbett
3 days, 2 hours ago -
Some advice for managing my wireless internet gateway
by
LHiggins
2 days, 10 hours ago -
NO POWER IN KEYBOARD OR MOUSE
by
HE48AEEXX77WEN4Edbtm
1 day, 12 hours ago -
A CVE-MITRE-CISA-CNA Extravaganza
by
Nibbled To Death By Ducks
3 days, 19 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.