WannaCry: The Patch Existed for Two Months. Why Wasn't It Installed?
WannaCry is spreading through networks using a flaw Microsoft patched in March. What the worm teaches about patch cadence, EOL systems and tested backups.
Want this checked continuously?
CompleteStatus grades your headers, SSL and email security 24/7 — free, commercial use allowed.
As we write this, a ransomware worm called WannaCry is four days into its spread. Since Friday it has hit hundreds of thousands of machines by current estimates, in well over a hundred countries, encrypting files, demanding around $300 in bitcoin, and moving to the next machine without anyone clicking anything. In the UK, NHS hospitals canceled appointments and diverted ambulances. Factories paused production lines. New variants are reportedly already circulating.
The fact that matters most: the vulnerability WannaCry exploits was patched by Microsoft in March, two months before the outbreak. Every encrypted machine was one Windows Update cycle away from being immune. This is a story about maintenance.
How the worm spreads
WannaCry is a worm in the classic sense. It doesn't need phishing emails or user mistakes to move. It scans for machines exposing SMBv1 (Windows file sharing, port 445) and exploits a flaw using EternalBlue, one of the purported NSA tools the Shadow Brokers group published in April. Once inside, it encrypts files, shows its ransom note, and starts scanning for new victims on the local network and the public internet.
Ransomware usually spreads as fast as people open attachments. WannaCry spreads as fast as a network scan. One exposed, unpatched machine on a flat network can lead to an entire organization being encrypted before lunch.
The kill switch
Friday's outbreak slowed for an odd reason. A security researcher noticed the malware queried a long, gibberish domain name before doing its work, and the domain was unregistered. He registered it for a few dollars, and it turned out to act as a kill switch: when the domain resolves, the malware stops. That registration is credited with blunting the first wave.
Don't take much comfort from it. Variants without the kill switch are already being reported, and the underlying exploit works as well today as it did on Friday. The kill switch bought time to patch. It isn't the patch.
The patch shipped in March
Microsoft fixed the SMBv1 flaw on March 14th in security bulletin MS17-010, rated critical. Over the weekend they took the unusual step of publishing emergency patches for Windows XP and Server 2003, which stopped receiving security updates years ago. When a vendor patches unsupported systems, it's telling you how bad things are.
So the useful question isn't how the attackers did it, but why so many machines were still vulnerable two months after the fix. The answers are familiar: patching is disruptive, reboots need scheduling, some machine runs software that "can't" be touched, nobody owns the process, and there's always a more urgent ticket.
The lessons are about process
-
Patch cadence is a process, not an event. If you patched because of the headlines, your process is the headlines. A working process has a fixed monthly cycle for routine updates, a fast lane measured in days for critical, actively exploited vulnerabilities, a test group that gets patches first, and a named person who owns the schedule. MS17-010 was rated critical in March and the exploit was public by mid-April. Both signals came well before Friday.
-
End-of-life systems need a plan. Every network has them: the XP box that drives a lab instrument, the ticket kiosk, the machine running the one application nobody ported. "We can't upgrade it" may be true, but "so we'll do nothing" doesn't follow. Isolate them on segmented networks, block SMB at their boundary, keep them off the internet, and write down where they all are. Unsupported and unknown is the combination that ends up in the news.
-
Backups you've actually restored. The real remedy for ransomware is a backup it can't reach: offline or otherwise disconnected copies, not just a synced folder (sync will happily replicate your encrypted files over the good ones). An untested backup is a guess. Schedule real restore drills, verify the restored data and time them. Knowing in advance that a restore takes six hours is useful; finding out mid-incident that it takes six days is a disaster.
-
Know your exposure before someone else maps it. WannaCry found victims by scanning. You can run the same scan first, on networks you're authorized to test:
# Which of our machines answer SMB? (your own ranges only)
nmap -p 445 --open 203.0.113.0/24
Anything answering on 445 to the public internet needs attention today. While you're at it, disable SMBv1 entirely. It's a protocol from another era, and this week makes the argument for you.
Maintenance is the security program
No zero-day was involved this week, no defense had to be invented, and nothing WannaCry did was unpreventable with tools everyone already had. The organizations in the headlines aren't there because the attackers were brilliant. They're there because patching, inventory and backups are unglamorous, and unglamorous work loses scheduling battles until it suddenly doesn't.
CompleteStatus is built around the same habit of knowing your systems' state before events force the issue: continuous external checks on your sites, endpoints and SSL certificates, with alerts when something changes. See the features page, or create a free account. But first, tonight: check that MS17-010 is actually installed everywhere you think it is.
Written with AI assistance and reviewed by the CompleteStatus team.
Get notified when CompleteStatus opens
New accounts are closed while we're in private beta. Leave your email and we'll send one message the moment sign-ups open — nothing else.