Microsoft says be prepared for RDP attack within the next 30 days
Microsoft has released 6 updates in this month's patch Tuesday, including a patch for a critical hole which the software maker warns could be hit within the next 30 days.
The flaw covers all current versions of Windows and is found in the Remote Desktop Protocol (RDP) and allows for attackers to run code remotely. Although Vista users and above can activate the remote desktop network level authentication. In addition, RDP is usually disabled by default.
Microsoft had this to say in a posting on their Security Research Centre Blog: "We are not aware of any attacks in the wild. However, due to the attractiveness of this vulnerability to attackers, we anticipate that an exploit for execution will be developed in the next 30 days.”
Among the other patches that Microsoft has issued, 4 are also marked as important. A DLL preloading issue in Expression Design has been fixed and Visual Studio's add on also gets an issue resolved. In addition fixes for kernel and DNS system level issues have also been addressed.