Windows under attack by zero-day flaw — what to do right now

A laptop running Windows 11, representing an article about how to use task scheduler on windows
(Image credit: sdx15 / Shutterstock)

Are you using a Windows PC? Then stop what you’re doing and check that you’re running the latest update, as it fixes some security holes hackers have been actively exploiting. 

As Beeping Computer reports, the security tweaks bundled in the June 2022 cumulative Windows Updates seal the zero-day security hole that enabled an exploit dubbed Follina (CVE-2022-30190). 

The security flaw came in the form of a Microsoft Windows Support Diagnostic Tool (MSDT) remote code execution bug, which allowed hackers to execute arbitrary code within apps using the tool, and allow the installation of programs, changing or deleting of data or making a new Windows account with a compromised user’s rights on the affected PC. The bug affects machines running Windows 7 or later. 

And according to security researchers from Proofpoint, the bug has been exploited by Chinese hackers who used it to send malicious documents to Tibetans. Furthermore, the bug has been used to target U.S. and European Union government agencies. 

So while you may not be the target of potential state-sponsored hackers, other savvy cyber criminals could look to use the exploit on unpatched PCs to cause havoc. That's why, like Microsoft, we recommend you make sure your PC is patched as soon as possible. 

"Microsoft strongly recommends that customers install the updates to be fully protected from the vulnerability. Customers whose systems are configured to receive automatic updates do not need to take any further action," said Microsoft.

So if you have automatic updates enabled then there's a good chance you’re already protected. But if not you’ll want to ensure you have the latest patch. 

To do that, head to the Windows Settings app, navigate to the Windows Update section and you should be told if your PC is up to date, if it needs an update, or in some cases if a restart is needed to apply the update. Make sure you do this to help keep your PC protected from malicious and opportunistic hackers. 

Roland Moore-Colyer

Roland Moore-Colyer a Managing Editor at Tom’s Guide with a focus on news, features and opinion articles. He often writes about gaming, phones, laptops and other bits of hardware; he’s also got an interest in cars. When not at his desk Roland can be found wandering around London, often with a look of curiosity on his face. 

Read more
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
How to disable the Windows key
Microsoft patches over 160 security flaws including 3 active zero days — update your PC right now
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
Google Pixel 9 held in the hand.
Google just fixed a zero-day kernel flaw used by hackers and 47 other vulnerabilities — update your Android phone right now
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
Apple iPhone 16 held in the hand.
iOS 18.3.1 — update your iPhone right now to fix critical zero-day vulnerability
Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Latest in News
A mosquito resting on a plant
Experts predict a spring surge in these 9 pest populations — here's what's forecast for your area
Apple Watch SE (2022) shown on wrist
Apple Watch SE 3 reportedly in ’serious jeopardy’ — here’s why
Galaxy S25 Plus held in the hand.
Samsung could delay One UI 7’s release in the US — here’s what we know
Claude AI on phone sitting on keyboard
Claude 3.7 Sonnet now supports real-time web searching — but there's a catch
Nintendo Switch 2
Nintendo Switch 2 pre-order date just tipped — here's when you might be able to buy
Apple iPhone 16 & 16 Plus hands-on.
iPhone 17 just tipped for this long overdue Pro feature in new report