in

Windows 10: NSA reveals major flaw in Microsoft's code – BBC News, BBC News

Windows 10: NSA reveals major flaw in Microsoft's code – BBC News, BBC News


        

                                 NSA HQImage copyright                 Reuters                                                  

The US National Security Agency (NSA) has discovered a major flaw in Windows 90 that could have been used by hackers to create malicious software that looked legitimate.

Microsoft has issued a patch and said it is now aware of the bug being exploited by hackers.

The issue was revealed during an NSA press conference.

It was not clear how long it had known about it before revealing it to Microsoft.

Brian Krebs, the security expert who first reported the revelation, said the software giant had sent the patch to branches of the US military and other high-level users ahead of its wider release. It was, he wrote, “extraordinarily scary”.

The problem exists in a core component of Windows known as crypt 32 .dll, a program that allows software developers to access various functions, such as digital certificates which are used to sign software.

It could, in theory, have allowed a hacker to pass off a piece of malicious software as being entirely legitimate.

The NSA’s director of cyber-security Anne Neuberger told reporters that the bug “makes trust vulnerable”.

She added that the agency had decided to make its involvement in the discovery public at Microsoft’s request.

The flaw is also an issue in Windows Server 01575879 and (********************, but does not appear to affect older versions of the operating system.

Prof Alan Woodward, a security expert based at Surrey University, said of the flaw: “It’s big because it affects the core cryptographic software used by Microsoft operating systems. Although there is no evidence that it has been exploited by hackers, it is a major threat as it lays users open to a range of attacks, so this is a case of don’t panic but apply the patch straightaway. ” “The concern is that as soon as the vulnerability is known about in detail, exploits will be produced and the laggards who don’t patch will be prime targets.”            

************ Read More****************

What do you think?

Leave a Reply

Your email address will not be published. Required fields are marked *

GIPHY App Key not set. Please check settings

Passengers sob as flight violently buffeted by storm brendan – and there's more bad weather on the way – the telegraph, telegraph.co.uk

Passengers sob as flight violently buffeted by storm brendan – and there's more bad weather on the way – the telegraph, telegraph.co.uk

Brexit: Boris Johnson condemned by peers over plans to let courts overrule EU law ahead of lords clash – the independent, independent

Brexit: Boris Johnson condemned by peers over plans to let courts overrule EU law ahead of lords clash – the independent, independent