Microsoft issues fix for critical Windows flaw disclosed by the NSA

Subscribers:
4,200
Published on ● Video Link: https://www.youtube.com/watch?v=4rIPdlgZbSA



Duration: 2:44
250 views
1


Reported today on TechSpot

For the full article visit: https://www.techspot.com/news/83551-microsoft-issues-fix-critical-windows-flaw-disclosed-nsa.html

Microsoft issues fix for critical Windows flaw disclosed by the NSA

Sometimes help comes from unexpected places

What just happened? Few things are more terrifying than receiving a warning from the National Security Agency (NSA), and that's exactly what happened to Microsoft yesterday. The intelligence organization discovered a severe flaw in Windows, and instead of harnessing that knowledge to further their own goals, the NSA's programmers disclosed it directly to Microsoft.

According to security news site KrebsonSecurity, the flaw in question resides in crypt32.dll, a Windows module that handles "certificate and cryptographic messaging functions in the CryptoAPI."

Krebs says CryptoAPI allows developers to "secure Windows-based applications using cryptography," among other things. If compromised, crypt32.dll could allow bad actors to spoof digital signatures on malware, making viruses appear legitimate while hiding far nastier surprises inside.

The site also says a vulnerability in this component may negatively impact the security of various Windows 10 features, including (but not limited to) "authentication on Windows desktops and servers," and the protection of sensitive data sent over the web via Microsoft Edge and Internet Explorer.

I get the impression that people should perhaps pay very close attention to installing tomorrow's Microsoft Patch Tuesday updates in a timely manner. Even more so than others.

I don't know... just call it a hunch?

¯\_(ツ)_/¯

- Will Dormann (@wdormann) January 13, 2020

Though Krebs speculates that "all versions of Windows" are likely to have been affected by this vulnerability (crypt32.dll has been in use since the early days of Windows), the NSA has so far only con




Other Videos By Colin Boyd SEO


2020-01-14Amazon to invest $1 billion to digitize small businesses in India
2020-01-14Reading Ted Chiang’s ‘The Merchant and the Alchemist’s Gate’
2020-01-14Four years after being acquired, Hipmunk is shutting down
2020-01-14GaN chargers are still worth getting excited about
2020-01-14Hipmunk’s co-founders tried to buy it back before the shutdown
2020-01-14Paper-rich startup employees look for ‘pre-wealth’ help to lock down stock options
2020-01-14Delta Air Lines’ startup partnerships are fueling innovation
2020-01-14Rocket Lab to open a new combined HQ, mission control and production facility in Long Beach
2020-01-14Don’t be a selfless startup
2020-01-14Obvious Ventures closes an irrationally sized third fund
2020-01-14Microsoft issues fix for critical Windows flaw disclosed by the NSA
2020-01-14Microsoft is rolling out its Chromium-based Edge browser today
2020-01-14DC officially connects the TV and film universes in surprise Crisis cameo - CNET
2020-01-14US Navy has secret video of UFO encounter, report says - CNET
2020-01-14GMC Terrain AT4 rounds out the lineup - Roadshow
2020-01-14Oscars 2020: How to watch the awards show and red carpet online - CNET
2020-01-14Lucid Air is getting its public debut in New York in April - Roadshow
2020-01-142020 Genesis GV80 revealed in its final form - Roadshow
2020-01-14Porsche Taycan Turbo S has an official EPA range, and it's not that great - Roadshow
2020-01-14DJI brings back the Phantom drone, a year after it vanished from stores
2020-01-14Trump attacks Apple in push to weaken encryption - CNET