Microsoft released emergency security updates for severe remote code execution flaws that affected both supported and legacy Windows systems, including unusual patches for end-of-life platforms such as Windows XP, Windows Server 2003, and Windows Vista. One of the most serious cases was CVE-2019-0708 (BlueKeep), a pre-authentication vulnerability in Remote Desktop Services that Microsoft and security researchers warned was wormable, meaning malware could spread between vulnerable machines without user interaction. Microsoft directed customers on unsupported systems to obtain out-of-band fixes through the Microsoft Update Catalog, while researchers urged organizations to patch exposed RDP services immediately.
Microsoft had taken a similar extraordinary step earlier for a critical Internet Explorer zero-day affecting IE 6 through IE 11, issuing an emergency update even for retired Windows XP after active exploitation expanded in the wild. Reporting at the time said attackers were using malicious websites to trigger remote code execution and broadened targeting from defense and financial firms to government and energy organizations. Later coverage of BlueKeep warned that public exploit explanations increased the risk of destructive attacks, reinforcing concerns that unpatched legacy Windows systems remained a high-value entry point for widespread compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
An explainer describing how to exploit the wormable BlueKeep vulnerability was posted online on GitHub. Reporting said the publication increased concern that destructive or widespread exploitation could follow.
McAfee released a blog post explaining the BlueKeep RDP flaw, emphasizing its wormable nature and the need for urgent patching. The write-up helped publicize technical understanding of CVE-2019-0708 after Microsoft's advisory.
Microsoft published customer guidance for CVE-2019-0708, a critical wormable Remote Desktop Services remote code execution vulnerability. It also released out-of-band updates for unsupported platforms including Windows XP, Windows Server 2003, and Windows Vista, urging organizations to patch immediately.
An optional update for the Visual Studio 2010 Tools for Office Runtime was pulled within about two hours of release after reports that it caused update hangs on some systems. The withdrawal occurred alongside the February 2015 Patch Tuesday rollout.
Microsoft released nine Patch Tuesday bulletins, including three rated Critical, covering vulnerabilities in Internet Explorer, Windows, Office, and other components. Key fixes included MS15-009 for Internet Explorer, MS15-010 for Windows kernel TrueType font handling, and MS15-011 for a domain-related Windows flaw triggered when connecting to an untrusted network.
Researcher Jeff Schmidt, then working for ICANN, reported a Windows vulnerability later tracked as MS15-011 to Microsoft. The flaw ultimately required substantial operating system re-engineering to fix.
FireEye said exploitation of the Internet Explorer zero-day had expanded beyond IE 9–11 on Windows 7 and 8 to include Windows XP users running IE 8. It also reported that multiple new threat actors were using the exploit and broadening targeting from defense and finance to government and energy organizations.
Microsoft issued an out-of-band security update for Internet Explorer 6 through 11 on supported Windows versions and also for retired Windows XP. The patch addressed a critical remote code execution flaw that was being actively exploited via malicious websites.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
support.microsoft.com
Open sourceweb.archive.org
Open sourcemcafee.com
Open sourcemsrc-blog.microsoft.com
Open sourcezdnet.com
Open sourcearstechnica.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.