Experts sound worm alarm for critical Windows bug

13.03.2012

"Absolutely, this will be very attractive to hackers," said Amol Sarwate, manager of Qualys' vulnerability research lab, echoing Storms and Miller. "It doesn't look like it's that complicated to come up with the code sequence [to trigger the bug]."

Microsoft raised all its usual flags, and more, for MS12-020, tagging it with an exploitability index rating of "1," meaning it expects reliable exploits to appear within 30 days, and ranking the update as the one to patch before all others.

In a post to the company's (SRD) blog, Suha Can and Jonathan Ness, a pair of Microsoft engineers, went even further. "[We] strongly encourage you to make a special priority of applying this particular update," said Can and Ness.

Ideally, customers will quickly apply the patch, but Microsoft also offered a temporary workaround.

The workaround, which Microsoft automated using its Fix-it support tool, adds another layer of security by requiring Network Level Authentication, or NLA, to force authentication before an RDP session begins. The Fix-it tool applies to Windows Vista, Windows 7, Server 2008 and Server 2008 R2.