…“The vulnerable driver ships with every version of Windows, up to and including Server 2025,” Adam Barnett, lead software engineer at Rapid7, said. “Maybe your fax modem uses a different chipset, and so you don’t need the Agere driver? Perhaps you’ve simply discovered email? Tough luck. Your PC is still vulnerable, and a local attacker with a minimally privileged account can elevate to administrator.”…

  • NotMyOldRedditName@lemmy.world
    link
    fedilink
    English
    arrow-up
    98
    arrow-down
    1
    ·
    1 day ago

    People have probably been sitting on exploits for months or longer. There will probably be another wave after the 1 year extended support ends.

    • REDACTED@infosec.pub
      link
      fedilink
      English
      arrow-up
      8
      ·
      10 hours ago

      If I remember correctly, MS still pushed some critical patches to Win7 after the support ended as they realized 1/3 of world’s computers turning into botnets is probably not in their interests.

      • Attacker94@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        7 hours ago

        Except they will stay on their high horse and only give it to extended support this time around, that way they get what they want and they’ll be able to spin it against the people who didn’t opt in.