I was curious about the “every version ever shipped.”
This gets really old school.
Comment on Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever Shipped
paraphrand@lemmy.world 1 week ago
It’s interesting that this supposedly goes back to Windows 3.1?
I was curious about the “every version ever shipped.”
This gets really old school.
Personally I blame Dave Plummer.
Ah yes the 0-decade vulnerability…
Boi will I miss the ever-encompasing shield of Microsoft when my Windows 10 stops receiving updates…
makes you wonder if/how/by who its been used all these years
I expect it’s stuff like ATMs, Coinstar machines. Things that may need to phone home regularly but don’t need to sit online constantly.
SnotFlickerman@lemmy.blahaj.zone 1 week ago
Other articles make more clear why that is.
cyberpress.org/windows-agere-modem-driver-0-day-f…
So maybe not all the way back to the original release, but back to the first release that included this specific telephony modem driver,
ltmdm64.sys. If I recall correctly, Windows 3.1 brought networking capabilities.However, another article claims it has only been shipped with every version of Windows since 2006.
thestack.technology/windows-users-hacked-due-to-l…
paraphrand@lemmy.world 1 week ago
Thanks for the details!
I wonder how often they clean stuff up like this. That crossed my mind earlier, I’m sure there is a bunch of “dormant” software that could be cleaned out or made optional in some way.
I’m sure the making it optional idea is easier said than done. Especially from a standpoint of discoverability and usability.
SnotFlickerman@lemmy.blahaj.zone 1 week ago
Right, it was referenced in one of the articles that a bunch of legacy industrial machines likely still use this hardware, so they’re probably going to have to go dig up PCI modems from that era without the Agere/Lucent chipset.
adespoton@lemmy.ca 1 week ago
People using that legacy hardware generally can’t run Windows 10, which just ended support this month. The patch is only for Windows 11, which won’t run on older hardware.
muusemuuse@sh.itjust.works 1 week ago
That’s still a lot of people that use that damn driver. I know at least in medical billing there’s always someone still using a damn fax machine. Almost every claim passes through fax technology at some point, although more and more of it is being emulated.
Where I work, it’s used mostly by emergency rooms that don’t want to use anything else.
This is not an environment where you want an exploit.
GaryGhost@lemmy.world 1 week ago
Time to move that paper hybrid system to a full EHR.
floquant@lemmy.dbzer0.com 1 week ago
Are there any figures for how widespread that Agere chip is? I wonder if any German companies are going to be bit in the aas by this lol