Feeds

Microsoft warns of post-April zero day hack bonanza on Windows XP

Beginning April 2014, patches will bring new threats

Beginner's guide to SSL certificates

Microsoft has a Windows XP problem: people still like it and aren't willing to upgrade just yet. So it's warning users that if they don’t upgrade soon, hackers will lie in wait each new Patch Tuesday to reverse-engineer a full set of new vulnerabilities.

"The very first month that Microsoft releases security updates for supported versions of Windows, attackers will reverse engineer those updates, find the vulnerabilities and test Windows XP to see if it shares those vulnerabilities," said Tim Rains, Microsoft's director of trustworthy computing, in a blog post.

"If it does, attackers will attempt to develop exploit code that can take advantage of those vulnerabilities on Windows XP. Since a security update will never become available for Windows XP to address these vulnerabilities, Windows XP will essentially have a 'zero day' vulnerability forever."

He points out that from July 2012 through July 2013, Windows XP received 45 patches, 30 of which were relevant to Windows 7 and 8 as well, and there is considerable flaw cross-over found among the three operating systems. XP is also by far the most malware-infected operating systems, he points out.

Windows XP virus infection rates

Open season on XP from malware

Hackers have learned to get around XP systems like Data Execution Prevention (DEP), Rains warned, although it has forced attackers to up their game somewhat. The threat landscape has also changed significantly since the last service pack for XP came out in 2008 – five years is a very long time in the malware industry, after all.

Windows XP, despite being 12 years old, is still Microsoft's second most popular operating system with 37.2 per cent of desktops compared to 44.5 per cent for Windows 7. Don't ask about Windows 8 – that has only just overtaken the much-reviled Vista.

Despite the ending of free XP security updates on April 8 of next year, Rains says he still meets businesses that run XP on some systems and plan to continue doing so until the hardware fails. According to recent data, 15 per cent of IT managers running XP don't even realize support is ending, and they are going to have to shell out for premium support for security holes.

But it now looks certain that a large percentage of XP users still won't be upgrading any time soon. Certainly if you're running an enterprise XP system, you may have postponed an upgrade for too long to ensure an orderly transition – although resellers will be happy to help.

At last year's Worldwide Partners Conference, Microsoft described the upgrade market for Windows XP as a $12bn opportunity for the channel. Based on current usage stats, resellers have a long way to go before realizing that kind of cash. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Microsoft on the Threshold of a new name for Windows next week
Rebranded OS reportedly set to be flung open by Redmond
'In... 15 feet... you will be HIT BY A TRAIN' Google patents the SPLAT-NAV
Alert system tips oblivious phone junkies to oncoming traffic
Apple: SO sorry for the iOS 8.0.1 UPDATE BUNGLE HORROR
Apple kills 'upgrade'. Hey, Microsoft. You sure you want to be like these guys?
SMASH the Bash bug! Apple and Red Hat scramble for patch batches
'Applying multiple security updates is extremely difficult'
ARM gives Internet of Things a piece of its mind – the Cortex-M7
32-bit core packs some DSP for VIP IoT CPU LOL
Lotus Notes inventor Ozzie invents app to talk to people on your phone
Imagine that. Startup floats with voice collab app for Win iPhone
'Google is NOT the gatekeeper to the web, as some claim'
Plus: 'Pretty sure iOS 8.0.2 will just turn the iPhone into a fax machine'
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.