Experts sound worm alarm for critical Windows bug

13.03.2012

Windows XP and Server 2003, however, do not support NLA; for the former, Microsoft's released an additional Fix-it tool that adds NLA support to Windows XP Service Pack 3 (SP3) desktops and laptops.

Links to the Fix-it tools can be found on the SRD blog.

Several researchers applauded Microsoft's workarounds, in large part because unlike the patch, they don't require a system reboot, which may make server administrators skittish about applying MS12-020 itself.

"NLA a really good option," said Wolfgang Kandek, chief technology officer at Qualys. He and others expect that many Microsoft customers will enable NLA first, then later patch the vulnerability by deploying MS12-020.

"It's going to be enough to mitigate the first wave of attacks," argued Storms, of enabling NLA.