After latest Microsoft Win updates some PCs running Sophos AV not boot
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-0708 | Unauthenticated RCE in Microsoft Remote Desktop Services (BlueKeep) CVE-2019-0708 is a use-after-free (CWE-416) vulnerability in Microsoft Remote Desktop Services, formerly Terminal Services, in which an unauthenticated attacker can connect to a target system over RDP and send specially crafted requests to trigger the flaw. Because the trigger requires no authentication, the flaw is wormable: a successful exploit grants remote code execution on the target host, potentially with elevated privileges, and could allow self-propagating attacks similar to WannaCry. Organizations running the affected Microsoft Remote Desktop Services, particularly legacy Windows releases still accepting inbound RDP connections, are in scope. Exploitation is confirmed in the wild: the flaw (nicknamed BlueKeep) is listed in CISA's KEV catalog (added 2021-11-03), CISA notes known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days. Do: Apply Microsoft's security updates for CVE-2019-0708 per vendor instructions, prioritizing legacy or end-of-support Windows systems exposed to inbound RDP. As mitigation, restrict RDP (TCP 3389) to trusted networks or VPN access, require Network Level Authentication (NLA), and audit perimeter firewalls and public scans for open RDP listeners. The vulnerability is in the CISA KEV catalog, so patching is treated as a required action for federal and high-risk environments. | 9.8 | 100% | KEV ransomware PoC ×4 |
| masson the order of millions of internet-exposed RDP endpoints and far more internal systems |
Full article481 words · extracted from securityaffairs.com · click to collapse

Sophos is warning users of potential problems with the recent Microsoft’s Patch Tuesday updates and is saying to roll back it if they want the PC to boot.
The security firm has informed its customers of potential problems with the latest Microsoft’s Patch Tuesday updates and is asking them to uninstall the patch if they want the machine to boot.
This means that the machine could be exposed to cyber attacks that leverage the vulnerabilities addressed by Microsoft, including a Windows zero-day flaw and an RDS vulnerability that can be exploited to carry out WannaCry-like attack.
Sophos confirmed that the latest set of Windows updates are causing problems with the boot of computers running the popular Antivirus software.
“We have had a few customers reporting that following on from the Microsoft Windows 14th May patches they are experiencing a hang on boot where the machines appear to get stuck on “Configuring 30%”” reads a note published by the company.
Experts believe the problems could be caused by the incompatibility with the KB4499164 and KB4499175 Microsoft Patches released on May 14, 2019.
According to Sophos, the problems have been reported by customers running Windows 7 and Windows Server 2008 R2.

The experts suggest to remove Windows update by booting the system in Safe mode.
“Current reports indicate that removing the Windows update in Safe Mode allows computers to boot as normal.” continues the note.
“If you experience issues removing this in Safe Mode please set the “Sophos Anti-Virus” Service startup to be “Disabled” and then attempt to remove the update after coming out of Safe Mode.”
Sophos is currently working with Microsoft to investigate the issue and develop a fix.
Microsoft Patch Tuesday updates for May 2019 also addressed a remote code execution flaw in Remote Desktop Services (RDS). The flaw tracked as CVE-2019-0708 can be exploited by an unauthenticated attacker by connecting to the targeted system via the Remote Desktop Protocol (RDP) and sending specially crafted requests. Microsoft pointed out that this vulnerability could be exploited by malware with wormable capabilities. It could be triggered by an unautheticated attacker and without users interaction, making it possible for malware to spread in an uncontrolled way into the target networks.
The problem faced by Sophos customers could very annoying for large businesses that deployed the Microsoft updates. One user commenting on a blog post published by Sophos wrote the following statement:
“We had to roll back some 300+ machines for clients around the US.”
Affected users that are not able to boot their machine have to contact the company and open a ticket with the tech support team.
Thank you
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – Sophos, Microsoft)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/85919/security/microsoft-problems-sophos-av.html