Microsoft updates break AV software, again!
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-0708 | Unauthenticated RCE in Microsoft Remote Desktop Services (BlueKeep) CVE-2019-0708 is a use-after-free (CWE-416) vulnerability in Microsoft Remote Desktop Services, formerly Terminal Services, in which an unauthenticated attacker can connect to a target system over RDP and send specially crafted requests to trigger the flaw. Because the trigger requires no authentication, the flaw is wormable: a successful exploit grants remote code execution on the target host, potentially with elevated privileges, and could allow self-propagating attacks similar to WannaCry. Organizations running the affected Microsoft Remote Desktop Services, particularly legacy Windows releases still accepting inbound RDP connections, are in scope. Exploitation is confirmed in the wild: the flaw (nicknamed BlueKeep) is listed in CISA's KEV catalog (added 2021-11-03), CISA notes known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days. Do: Apply Microsoft's security updates for CVE-2019-0708 per vendor instructions, prioritizing legacy or end-of-support Windows systems exposed to inbound RDP. As mitigation, restrict RDP (TCP 3389) to trusted networks or VPN access, require Network Level Authentication (NLA), and audit perimeter firewalls and public scans for open RDP listeners. The vulnerability is in the CISA KEV catalog, so patching is treated as a required action for federal and high-risk environments. | 9.8 | 100% | KEV ransomware PoC ×4 |
| masson the order of millions of internet-exposed RDP endpoints and far more internal systems |
Full article303 words · extracted from helpnetsecurity.com · click to collapse
Microsoft’s May 2019 security fixes have again disrupted the normal functioning of some endpoint security products on certain Windows versions.

Current problems
“We have had a few customers reporting that following on from the Microsoft Windows 14th May patches they are experiencing a hang on boot where the machines appear to get stuck on ‘Configuring 30%’,” UK-based Sophos explained.
“We have currently only identified the issue on a few customers running Windows 7 and Windows Server 2008 R2.”
Sophos is working on fixing the problem. In the meantime, users of Sophos Endpoint Security and Control and Sophos Central Endpoint Standard/Advanced have been advised to remove the “offending” Windows updates (KB4499164 or KB4499165) for the AVs to work, and delay the patching until Sophos delivers the update that will fix the conflict.
Microsoft’s monthly rollup update has also negatively affected systems that have McAfee Endpoint Security (ENS) Threat Prevention 10.x or McAfee Host Intrusion Prevention (Host IPS) 8.0 or McAfee VirusScan Enterprise (VSE) 8.8 installed.
Past problems
A similar situation has happened in April, when Microsoft’s updates impacted Sophos and several other AV vendors (McAfee, Avast, ArcaBit, Avira) and caused some customers using older Windows and Windows Server versions to occasionally experience system fails or hangs during boot up, slow startups, unresponsiveness at restart, or the inability to log in after applying the update.
Those issues were solved by emergency updates on behalf of the security companies and by Microsoft temporarily blocking the Microsoft update from being visible for download if the affected endpoint solutions were present on the system.
It is to be hoped that the AV companies will push out updates soon, as the May 2019 Microsoft updates fix some pretty serious vulnerabilities, including a “wormable” RDP flaw (CVE-2019-0708) that is expected to soon be widely exploited by attackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/05/21/microsoft-updates-break-av/