Microsoft patches Windows 10 security flaw discovered by the NSA

Subscribers:
4,200
Published on ● Video Link: https://www.youtube.com/watch?v=fiyg2dx6lwA



Duration: 2:50
341 views
4


Reported today on The Verge

For the full article visit: https://www.theverge.com/2020/1/14/21065563/microsoft-windows-security-flaw-nsa-patch-attribution-cryptography-update

Reported today in The Verge.

Microsoft patches Windows 10 security flaw discovered by the NSA

Microsoft is patching a serious flaw in various versions of Windows today after the National Security Agency (NSA) discovered and reported a security vulnerability in Microsoft's handling of certificate and cryptographic messaging functions in Windows. The flaw, which hasn't been marked critical by Microsoft, could allow attackers to spoof the digital signature tied to pieces of software, allowing unsigned and malicious code to masquerade as legitimate software.

The bug is a problem for environments that rely on digital certificates to validate the software that machines run, a potentially far-reaching security issue if left unpatched. The NSA reported the flaw to Microsoft recently, and it's recommending that enterprises patch it immediately or prioritize systems that host critical infrastructure like domain controllers, VPN servers, or DNS servers. Security reporter Brian Krebs first revealed the extent of the flaw yesterday, warning of potential issues with authentication on Windows desktops and servers.

Microsoft is now patching Windows 10, Windows Server 2016, and Windows Server 2019. The software giant says it has not seen active exploitation of the flaw in the wild, and it has marked it as "important" and not the highest "critical" level that it uses for major security flaws. That's not a reason to delay patching, though. Malicious actors will inevitably reverse-engineer the fix to discover the flaw and use it on unpatched systems.

It's unusual to see the NSA reporting these types of vulnerabilities directly to Microsoft, but it's not the first time the government agency has done so. This is the first time the NSA has accepted attribution from Microsoft for a vulnerabili




Other Videos By Colin Boyd SEO


2020-01-14First new comet of 2020 crashes into sun just after being discovered - CNET
2020-01-14Doom Slayer gets a new sword in latest Doom Eternal trailer - CNET
2020-01-14Billie Eilish nabs new James Bond theme song for No Time To Die - CNET
2020-01-14Doom Eternal's new trailer hints at drama in hell - CNET
2020-01-14You can now order a rack-mount Mac Pro for $6,500 - CNET
2020-01-14Sony launches new wireless camera grip to make it easier to vlog
2020-01-14Google Changes the Look of Paid and Organic Search Results on Desktop via @MattGSouthern
2020-01-14Avengers game delayed until September to add extra polish
2020-01-142020 Nissan Leaf is much the same with more content - Roadshow
2020-01-14Confirmed: Sony is skipping E3 for the second time
2020-01-14Microsoft patches Windows 10 security flaw discovered by the NSA
2020-01-14Scientists accidentally turn E. coli into beautiful bacterial art - CNET
2020-01-14Verizon launches privacy-focused search engine called OneSearch - CNET
2020-01-14CES 2020: Little robots are ready to make the world better in a big way - CNET
2020-01-14Fisker Ocean will make 300-plus HP, high-performance model planned - Roadshow
2020-01-14You soon will be able to Instagram DM from the web - CNET
2020-01-14Go watch this local TV news investigation about front blind spots in SUVs and trucks
2020-01-14GoDaddy’s new logo is a flattening of the personality-driven days of the early web
2020-01-14Apple’s rack-mounted Mac Pro variant is now available to order
2020-01-14Google buys Pointy to bring SMB store inventory online
2020-01-14DNA from detained immigrants will change the nature of the FBI’s genetic database