A friend got a new Windows 7 computer. His plan was to connect it to the internet and download all the Windows updates.
I told him a better strategy would be to download the patches from another system and then install them on his new computer before he connects it to the internet. My rationale is that his computer would be more susceptible to attacks until the system is patched.
But I started to wonder if my rationale is valid. Are there known attacks on an unpatched Windows 7 system if it is simply connected to the internet and is just sitting without being used? The system would have no third-party software, and he would not be using any tools like email or a web browser as he is downloading and installing patches.