Microsoft is patching a major Windows 10 flaw discovered by the NSA
In the past, the NSA might have kept the security hole to itself, using it to spy on adversaries. The best examples of that areWannaCry andEternalBlue, Windows 10 vulnerabilities discovered and exploited by the NSA for years. The agency developed hacking tools to exploit those holes, but unfortunately some of them were uncovered and released by a suspected Russian hacking group calledShadow Brokers. EternalBlue is still used to this day on unpatched systems for ransomware, theft and other types of attacks.
The NSA confirmed that the vulnerability affects Windows 10 and Windows Server 2016. It said that it flagged the dangerous bug because it "makes trust vulnerable." However, it wouldn't say when it found the flaw and declined to discuss it further until Microsoft released a patch.
I get the impression that people should perhaps pay very close attention to installing tomorrow's Microsoft Patch Tuesday updates in a timely manner. Even more so than others.
I don't know... just call it a hunch?
¯\_(ツ)_/¯— Will Dormann (@wdormann) January 13, 2020
According to Krebs, the vulnerability was found in a Windows component called crypt32.dll, which handles "certificate and cryptographic messaging functions," according to Microsoft. An exploit in that area could affect authentication on Windows desktops and servers, sensitive data on Microsoft's Internet Explorer and Edge browsers and many third-party applications. Hackers could supposedly also use it to spoof digital signatures, making malware look like a legitimate app.
A software patch has already been released to critical Windows 10 clients including the US military and managers of key internet infrastructure. Microsoft will reportedly release a patch to everyone else later today, and Krebs said it will be "a doozy of an update that will need to be addressed immediately by all organizations running Windows." This article will be updated once we hear more from Microsoft.
- 微软Surface Duo真机展示：支持手写笔 无后置摄像头
- .NET没有高薪？武汉15~30K 年终 分红，微软MVP Eleven的创业公司，只招.NET！
- Microsoft Halts a Global Fraud Campaign That Targeted CEOs
- 微软公开Windows 7源代码？真相了
- The fall of Microsoft’s Mixer and the fate of its exiles
- Windows10最新版怎么样？Windows 10 2004正式版体验评测
- 微软Windows 10全新“开始”菜单有哪些亮点？更加简洁统一！
- Windows 10新开始菜单设计更多信息曝光
- Amazon Prime Video launches Windows 10 desktop app
- 如何将AirPods与Win 10 PC相连
- What’s new in Windows 10 Build 2004
- windows10 2004版使用WSL2并自动转发WSL2中端口
- Windows 10 Start Menu upgrade might not be so radical after all
- Amazon is readying a Prime Video UWP app for Windows 10, preview spotted in the Store