Affected editions include the desktop-oriented Vista, Windows 7, Windows 8 and 8.1, and Windows RT, as well as Windows Server 2003, 2008 and 2012.
The vulnerability marked as having a critical severity rating, MS15-004, is found in the Telnet protocol, used to provide terminal connections to remote computers. Microsoft typically marks vulnerabilities as critical when they are already being misused by malicious parties to break into systems.
Telnet can be installed on all Windows systems, and is frequently used on the server editions, though the company hasn’t enabled it by default for the desktop since Windows Vista.
Administrators should also immediately tend to MS15-004, which describes a vulnerability in Windows 8.1 first brought to notice by Google’s Project Zero team on December 29. Google posted details of the vulnerability after waiting for Microsoft to respond, to no avail, for 90 days. Once a vulnerability is public knowledge, it can be abused by attackers.