ALL NEWS

NSA finds major security flaw in Windows 10, free fix issued

Jan 15, 2020, 6:20 AM

windows hack...

FILE - This Aug. 7, 2017, file shows a Microsoft Widows sign on display at a store in Hialeah, Fla. The National Security Agency has discovered a major security flaw in Microsoft's Windows operating system. Microsoft says the NSA notified the company about it. A fix was made available Tuesday, Jan. 14, 2020. (AP Photo/Alan Diaz)

(AP Photo/Alan Diaz)

The National Security Agency has discovered a major security flaw in Microsoft’s Windows 10 operating system that could let hackers intercept seemingly secure communications.

But rather than exploit the flaw for its own intelligence needs, the NSA tipped off Microsoft so that it can fix the system for everyone.

Microsoft released a free software patch to fix the flaw Tuesday and credited the intelligence agency for discovering it. The company said it has not seen any evidence that hackers have used the technique.

Amit Yoran, CEO of security firm Tenable, said it is “exceptionally rare if not unprecedented” for the U.S. government to share its discovery of such a critical vulnerability with a company.

Yoran, who was a founding director of the Department of Homeland Security’s computer emergency readiness team, urged all organizations to prioritize patching their systems quickly.

An advisory sent by the NSA on Tuesday said “the consequences of not patching the vulnerability are severe and widespread.”

Microsoft said an attacker could exploit the vulnerability by spoofing a code-signing certificate so it looked like a file came from a trusted source.

“The user would have no way of knowing the file was malicious, because the digital signature would appear to be from a trusted provider,” the company said.

If successfully exploited, attackers would have been able to conduct “man-in-the-middle attacks” and decrypt confidential information they intercept on user connections, the company said.

“The biggest risk is to secure communications,” said Adam Meyers, vice president of intelligence for security firm CrowdStrike.

Some computers will get the fix automatically, if they have the automatic update option turned on. Others can get it manually by going to Windows Update in the computer’s settings.

Microsoft typically releases security and other updates once a month and waited until Tuesday to disclose the flaw and the NSA’s involvement. Microsoft and the NSA both declined to say when the agency privately notified the company.

The agency shared the vulnerability with Microsoft “quickly and responsibly,” Neal Ziring, technical director of the NSA’s cybersecurity directorate, said in a blog post Tuesday.

Priscilla Moriuchi, who retired from the NSA in 2017 after running its East Asia and Pacific operations, said this is a good example of the “constructive role” that the NSA can play in improving global information security. Moriuchi, now an analyst at the U.S. cybersecurity firm Recorded Future, said it’s likely a reflection of changes made in 2017 to how the U.S. determines whether to disclose a major vulnerability or exploit it for intelligence purposes.

The revamping of what’s known as the “Vulnerability Equities Process” put more emphasis on disclosing vulnerabilities whenever possible to protect core internet systems and the U.S. economy and general public.

Those changes happened after a mysterious group calling itself the “Shadow Brokers” released a trove of high-level hacking tools stolen from the NSA, forcing companies including Microsoft to repair their systems. The U.S. believes that North Korea and Russia were able to capitalize on those stolen hacking tools to unleash devastating global cyberattacks.

We want to hear from you.

Have a story idea or tip? Send it to the KSL NewsRadio team here.

All News

Taylor Swift...

Jeff Caplan

Jeff Caplan’s Minute of News: Taylor Swift’s new album… for the non-Swifties

If you’re not a Swiftie, I’ll give you the cheat sheet so you can hold a conversation with anyone who’s lost in the Taylor Swift wormhole.

26 minutes ago

sign says "trans lives matter," the sign was for a protest about how slc school district was implem...

Heather Peterson

Implementation of new Utah bathroom law causes confusion in SLC School District

A new Utah bathroom law that takes effect on May 1 is at the center of some confusion about what schools do and don't need to do.

3 hours ago

Utah's water supply is doing well. Promontory Point during an EcoFlight around the Great Salt Lake....

Adam Small

Salt Lake having very dry April, but Utah’s water supply is still in top-notch shape

Utah's water supply is growing but Salt Lake City received a dry start to April. Utah might have something to worry about if May is dry.

3 hours ago

Speaker of the House Mike Johnson, R-La., , center, stops to talk to reporters just after lawmakers...

Stephen Groves, Lisa Mascaro and Kevin Freking

Ukraine, Israel aid advances in rare House vote as Democrats help Republicans push it forward

The House has pushed a $95 billion national security aid package for Ukraine, Israel and other U.S. allies closer to passage.

4 hours ago

Students participate in the groundbreaking ceremony for the new West Lake Jr. High building in 2022...

Kyle Remund

West Lake Jr. High rebuilds after 2020 earthquake

After being severely damaged in 2020, West Lake Jr. High is being rebuilt with earthquake safety in mind. KSL's Dave and Dujanovic interviewed Ben Horsley of Granite School District about how the new building is being brought up to seismic code and how the district is preparing for future emergencies.

5 hours ago

Former President Donald Trump speaks to the media as he enters Manhattan Criminal Court on Friday, ...

Associated Press

Trump’s legal team again asks appeals court to intervene in hush money case

A jury of 12 people and six alternates has been seated in former President Donald Trump's hush money trial in New York.

7 hours ago

Sponsored Articles

a person dressed up as a nordic viking in a dragon boat resembling the bear lake monster...

Bear Lake Convention and Visitors Bureau

The Legend of the Bear Lake Monster

The Bear Lake monster has captivated people in the region for centuries, with tales that range from the believable to the bizarre.

...

Live Nation Concerts

All the artists coming to Utah First Credit Union Amphitheatre (formerly USANA Amp) this summer

Summer concerts are more than just entertainment; they’re a celebration of life, love, and connection.

Mother and cute toddler child in a little fancy wooden cottage, reading a book, drinking tea and en...

Visit Bear Lake

How to find the best winter lodging in Bear Lake, Utah

Winter lodging in Bear Lake can be more limited than in the summer, but with some careful planning you can easily book your next winter trip.

Happy family in winter clothing at the ski resort, winter time, watching at mountains in front of t...

Visit Bear Lake

Ski more for less: Affordable ski resorts near Bear Lake, Utah

Plan your perfect ski getaway in Bear Lake this winter, with pristine slopes, affordable tickets, and breathtaking scenery.

front of the Butch Cassidy museum with a man in a cowboy hat standing in the doorway...

Bear Lake Convention and Visitors Bureau

Looking Back: The History of Bear Lake

The history of Bear Lake is full of fascinating stories. At over 250,000 years old, the lake has seen generations of people visit its shores.

silhouette of a family looking over a lake with a bird in the top corner flying...

Bear Lake Convention and Visitors Bureau

8 Fun Activities To Do in Bear Lake Without Getting in the Water

Bear Lake offers plenty of activities for the whole family to enjoy without having to get in the water. Catch 8 of our favorite activities.

NSA finds major security flaw in Windows 10, free fix issued