🧐 ProPicks AI October update is out now! See which stocks made the listPick Stocks with AI

Microsoft issues critical Windows security fix after tipoff from U.S. NSA

Published 01/14/2020, 07:25 PM
© Reuters. Microsoft holds device-launching event in Barcelona ahead of the 2019 Mobile World Congress
MSFT
-

By Raphael Satter

WASHINGTON (Reuters) - Microsoft Corp (O:MSFT) on Tuesday rolled out an important security fix after the U.S. National Security Agency tipped off the company to a serious flaw in its widely used Windows operating system, officials said.

Microsoft said the flaw could allow a hacker to forge digital certificates used by some versions of Windows to authenticate and secure data. Exploiting the flaw could have potentially serious consequences for Windows systems and users.

The NSA and Microsoft said they had not seen any evidence that the flaw had previously been abused, but both urged Windows users to deploy the update as soon as possible. NSA official Anne Neuberger noted that operators of classified networks had already been prodded to install the update and everyone else should now "expedite the implementation of the patch."

The Microsoft patch marks the first time the NSA has publicly claimed credit for prompting a software security update, although the agency said it has alerted companies in the past to flaws in their products. Neuberger said the agency was striving for more transparency with the information security research community.

"Part of building trust is showing the data," she told reporters in a call just minutes before the patch went live.

Experts said the move was unprecedented.

"I have never seen this before," said Tenable Chief Executive Amit Yoran, who previously served as founding director of the U.S. Computer Emergency Readiness Team.

"I cannot think of a single instance where government shared a zero-day with a vendor and took credit for it," he said in an email.

The NSA faces a balancing act when it comes across such vulnerabilities. The agency had been criticized after its cyberspies took advantage of vulnerabilities in Microsoft products to deploy hacking tools against adversaries and kept the Redmond, Washington-based company in the dark about it for years.

When one such tool was dramatically leaked to the internet in 2016, it was deployed against targets around the globe by hackers of all stripes.

In the most dramatic case, a group used the tool to unleash a massive malware outbreak dubbed WannaCry in 2017. The data-wiping worm wrought global havoc, affecting what Europol estimated was some 200,000 computers in more than 150 countries.

Neuberger did not directly address that controversy in her call but said that the NSA hoped to be "a good cybersecurity partner."

© Reuters. Microsoft holds device-launching event in Barcelona ahead of the 2019 Mobile World Congress

"We're working to evolve our mission," she said.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.