Breaking News

Viltrox launches AF 56mm Ultra-large aperture F1.2 Pro E and XF (APS-C) lenses Panasonic introduces AK-UBX100 4K multi-purpose camera Sony’s 360 Virtual Mixing Environment now available in Europe ASRock Releases AM5 Motherboard BIOS Update EnGenius Brings Wi-Fi 7 to Small Businesses with Affordable ECW510 Access Point

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Microsoft Releases Critical Windows Security Pathes Discovered by U.S. NSA

Microsoft Releases Critical Windows Security Pathes Discovered by U.S. NSA

PC components Jan 14,2020 0

Microsoft on Tuesday rolled out an important security fix after the U.S. National Security Agency tipped off the company to a serious flaw in its widely used Windows operating system.

The patches address the vulnerability CVE-2020-0601 in the usermode cryptographic library, CRYPT32.DLL, that affects Windows 10, Windows Seerver 2016 and Server 2019 systems. The vulnerability exists in the way Windows CryptoAPI validates Elliptic Curve Cryptography (ECC) certificates. This vulnerability is classed "Important" and Microsoft says it has not seen it used in active attacks.

An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. The user would have no way of knowing the file was malicious, because the digital signature would appear to be from a trusted provider.

A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software.

NSA official Anne Neuberger noted that operators of classified networks had already been prodded to install the update and everyone else should now “expedite the implementation of the patch.”

NSA had been criticized after its own cyberspies took advantage of vulnerabilities in Microsoft products to deploy hacking tools against adversaries and kept Microsoft in the dark about it for years.

When one such tool was leaked to the internet by a group, it was deployed against targets around the globe by hackers of all stripes. A group used the tool to unleash a massive malware outbreak dubbed WannaCry in 2017.

Tags: Cybersecuritywindows 10Microsoftnsa
Previous Post
iPhone Hacking Firm Cellebrite Updates Tool
Next Post
Disney+ App Outpaces Streaming Rivals With 40.9 Million Downloads

Related Posts

  • Snapdragon X Series is the Exclusive Platform to Power the Next Generation of Windows PCs with Copilot+ Today

  • Activision Blizzard King to Team Xbox

  • NVIDIA Studio Lineup Adds RTX-Powered Microsoft Surface Laptop Studio 2

  • Samsung and Microsoft Unveil First On-Device Attestation Solution for Enterprise

  • Introducing Xbox Game Pass Core, Coming This September

  • Announcing the next wave of AI innovation with Microsoft Bing and Edge

  • Microsoft Announces Security Copilot AI

  • Microsoft breaks new ground in healthcare with the next evolution of AI

Latest News

Viltrox launches AF 56mm Ultra-large aperture F1.2 Pro E and XF (APS-C) lenses
Cameras

Viltrox launches AF 56mm Ultra-large aperture F1.2 Pro E and XF (APS-C) lenses

Panasonic introduces AK-UBX100 4K multi-purpose camera
Enterprise & IT

Panasonic introduces AK-UBX100 4K multi-purpose camera

Sony’s 360 Virtual Mixing Environment now available in Europe
Consumer Electronics

Sony’s 360 Virtual Mixing Environment now available in Europe

ASRock Releases AM5 Motherboard BIOS Update
PC components

ASRock Releases AM5 Motherboard BIOS Update

EnGenius Brings Wi-Fi 7 to Small Businesses with Affordable ECW510 Access Point
Enterprise & IT

EnGenius Brings Wi-Fi 7 to Small Businesses with Affordable ECW510 Access Point

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Noctua NH-D15 G2

Noctua NH-D15 G2

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

Soundpeats Pop Clip

Soundpeats Pop Clip

be quiet! Pure Base 501

be quiet! Pure Base 501

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed