PATCH WATCH By Susan Bradley We’re starting the Windows 7 extended-support era … with more than our fair share of confusion. Before I shed some
[See the full post at: The trials and tribulations of Windows 7]
![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
The trials and tribulations of Windows 7
Home » Forums » Newsletter and Homepage topics » The trials and tribulations of Windows 7
- This topic has 4 replies, 4 voices, and was last updated 3 years, 3 months ago.
AuthorTopicTracey Capen
AskWoody MVPViewing 0 reply threadsAuthorReplies-
AlexEiffel
AskWoody_MVPSusan,
Thank you for your risk assessment report about Windows 7 post support-era.
About CVE-2020-0738, does it mean that you could get infected while browsing a web page on any browser? If so, it puts the risk at a whole different level than just having to avoid using IE.
Do you have any mitigation to suggest that doesn’t involve patches?
The way I see it, there is a very different category of risk using a PC where you need to download a malicious file and execute it to be infected vs just browsing the web and your browser displaying a tainted ad that will infect you without any other intervention.
A lot of people that consider themselves careful with computers might want to still run Windows 7 with a third-party browser for casual browsing and/or gaming and with nothing of much value on the PC they run it on, but I think it is important they have a good idea of the risk they get exposed.
Distinguishing between the different categories of risk and with the knowledge that it is exploited or not seem important.
-
Cybertooth
AskWoody PlusA reading of the NVD report for this vulnerability suggests that it’s the type of exploit that is typically delivered via a phishing e-mail or some other method that requires a specific action by a victim who has been targeted as a result of who they are or whom they work for. In other words, it’s highly unlikely that a random user will chance on this exploit merely by surfing the Web. Things would be different, though, if you are an employee of a large company, or of government.
Note that the exploitability score is 2.8 on a scale of 10. While no privileges are needed to take advantage of the flaw, it does require user interaction; see the Base Score Metrics for this value and hover the mouse pointer over “Required”.
-
Susan Bradley
Manager -
Susan Bradley
Manager
-
-
Viewing 0 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
numbering in a table (Awaiting moderation)
by
RopyDavits
5 hours, 18 minutes ago -
AMD Software Failed to Launch Because Windows Update Has Replaced the AMD…
by
Alex5723
7 hours, 55 minutes ago -
Microsoft : New macOS vulnerability, Migraine, could bypass System Integrity…
by
Alex5723
9 hours, 57 minutes ago -
Remove One Drive
by
crudolphy
15 hours, 17 minutes ago -
Firefox users on Windows 7, 8 and 8.1 moving to Extended Support Release
by
Alex5723
2 hours, 26 minutes ago -
How to change “User Account Control:Run as administrator”
by
DKThompson
19 hours, 35 minutes ago -
Two monitors, want different “fixed” wallpaper on each one
by
MauryS
1 day, 2 hours ago -
Microsoft forcing move to Microsoft account?
by
Tom
1 day ago -
Event 2545 Device Management – Enterprise – Diagnostics – Provider
by
Tex265
1 day, 3 hours ago -
QBot malware exploits Windows WordPad EXE to take over
by
Alex5723
1 day, 23 hours ago -
Laptop powers off during KB5026361 update
by
dhunter
1 day, 22 hours ago -
How to enable Sleep in Shut down menu?
by
Alex5723
2 days ago -
Beware of Google’s .ZIP domain and password-embedded URLs
by
B. Livingston
1 hour, 8 minutes ago -
Longstanding feature requests, and their status
by
Mary Branscombe
2 days, 8 hours ago -
Three typing tutors — no more “hunt and peck”
by
Deanna McElveen
2 days, 7 hours ago -
Is online banking secure?
by
Susan Bradley
55 minutes ago -
Bluetooth audio not working on older Lenovo T420 with Win 10
by
WSmsc0357
1 day, 13 hours ago -
Using wildcards in search and replace
by
Bob Karrow
2 days, 17 hours ago -
How is Windows XP an security risk?
by
Curious
1 day, 3 hours ago -
Is using VPN a good idea?
by
Tex265
2 days, 14 hours ago -
How to prevent/disable Bitlocker Automatic Device Encryption?
by
EricB
3 days, 1 hour ago -
Unexplained aspects of installing the latest update of Office 2021
by
TonyC
3 days, 1 hour ago -
Getting started with macOS Disk Utility: RAID, images, and repairs
by
Alex5723
3 days, 10 hours ago -
Getting started with macOS Disk Utility: Resizing, snapshots, and journaling
by
Alex5723
3 days, 10 hours ago -
Are you ready for AI?
by
Susan Bradley
3 hours, 31 minutes ago -
Windows 11 Insider Preview build 25375 released to Canary
by
joep517
3 days, 12 hours ago -
Windows 11 Insider Preview Build 22621.1825 and 22624.1825 released to BETA
by
joep517
3 days, 12 hours ago -
Duplicate image name brings up old images
by
Susan Bradley
4 days, 18 hours ago -
XP offline activation tool, xp_activate32.exe
by
Alex5723
2 days, 7 hours ago -
Huge Tesla leak reveals thousands of safety concerns, privacy problems
by
Alex5723
2 days, 20 hours ago
Recent blog posts
- Beware of Google’s .ZIP domain and password-embedded URLs
- Longstanding feature requests, and their status
- Three typing tutors — no more “hunt and peck”
- Is online banking secure?
- Are you ready for AI?
- MS-DEFCON 4: Skip those Secure Boot scripts
- Getting started with winget
- No NumLock key? Problem solved! Here’s the fix.
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2023 by AskWoody Tech LLC. All Rights Reserved.