ALL NEWS

NSA finds major security flaw in Windows 10, free fix issued

Jan 15, 2020, 6:20 AM

windows hack...

FILE - This Aug. 7, 2017, file shows a Microsoft Widows sign on display at a store in Hialeah, Fla. The National Security Agency has discovered a major security flaw in Microsoft's Windows operating system. Microsoft says the NSA notified the company about it. A fix was made available Tuesday, Jan. 14, 2020. (AP Photo/Alan Diaz)

(AP Photo/Alan Diaz)

The National Security Agency has discovered a major security flaw in Microsoft’s Windows 10 operating system that could let hackers intercept seemingly secure communications.

But rather than exploit the flaw for its own intelligence needs, the NSA tipped off Microsoft so that it can fix the system for everyone.

Microsoft released a free software patch to fix the flaw Tuesday and credited the intelligence agency for discovering it. The company said it has not seen any evidence that hackers have used the technique.

Amit Yoran, CEO of security firm Tenable, said it is “exceptionally rare if not unprecedented” for the U.S. government to share its discovery of such a critical vulnerability with a company.

Yoran, who was a founding director of the Department of Homeland Security’s computer emergency readiness team, urged all organizations to prioritize patching their systems quickly.

An advisory sent by the NSA on Tuesday said “the consequences of not patching the vulnerability are severe and widespread.”

Microsoft said an attacker could exploit the vulnerability by spoofing a code-signing certificate so it looked like a file came from a trusted source.

“The user would have no way of knowing the file was malicious, because the digital signature would appear to be from a trusted provider,” the company said.

If successfully exploited, attackers would have been able to conduct “man-in-the-middle attacks” and decrypt confidential information they intercept on user connections, the company said.

“The biggest risk is to secure communications,” said Adam Meyers, vice president of intelligence for security firm CrowdStrike.

Some computers will get the fix automatically, if they have the automatic update option turned on. Others can get it manually by going to Windows Update in the computer’s settings.

Microsoft typically releases security and other updates once a month and waited until Tuesday to disclose the flaw and the NSA’s involvement. Microsoft and the NSA both declined to say when the agency privately notified the company.

The agency shared the vulnerability with Microsoft “quickly and responsibly,” Neal Ziring, technical director of the NSA’s cybersecurity directorate, said in a blog post Tuesday.

Priscilla Moriuchi, who retired from the NSA in 2017 after running its East Asia and Pacific operations, said this is a good example of the “constructive role” that the NSA can play in improving global information security. Moriuchi, now an analyst at the U.S. cybersecurity firm Recorded Future, said it’s likely a reflection of changes made in 2017 to how the U.S. determines whether to disclose a major vulnerability or exploit it for intelligence purposes.

The revamping of what’s known as the “Vulnerability Equities Process” put more emphasis on disclosing vulnerabilities whenever possible to protect core internet systems and the U.S. economy and general public.

Those changes happened after a mysterious group calling itself the “Shadow Brokers” released a trove of high-level hacking tools stolen from the NSA, forcing companies including Microsoft to repair their systems. The U.S. believes that North Korea and Russia were able to capitalize on those stolen hacking tools to unleash devastating global cyberattacks.

We want to hear from you.

Have a story idea or tip? Send it to the KSL NewsRadio team here.

All News

Although the seed heads of bur buttercup look soft at first, they will stiffen up as they dry down,...

Michelle Lee

How to prevent bur buttercup from taking over your lawn

When you hear the phrase “bur buttercup,” you might think it sounds delightful and completely harmless. However, it can be one of the most rapidly-growing lawn weeds.

42 minutes ago

Camps have sprung up at several university campuses across Australia....

Hilary Whiteman and Angus Watson, CNN

Australian student protests show US campus divisions over Gaza war are going global

In the past 10 days, pro-Palestinian protest camps have appeared at seven Australian universities.

8 hours ago

Bobby Ratliff, left, and his wife, Theresa, hold hands a memorial service for their son, Odin, and ...

Becky Bruce

Parents of boy killed in meth-fueled, high speed crash sue Utah state agencies

Odin Ratliff and Hunter Jackson, both 3, were playing with their toy trucks in a corral outside Cedar Valley Stables in Eagle Mountain on May 2, 2022, when the driver crashed through multiple fences at over 100 miles per hour.

9 hours ago

President Elizabeth "Betsy" Cantwell, left, applauds after Gail Miller gave the commencement addres...

Collin Leonard, KSL.com

Gail Miller tells USU graduates to ‘lead with love’

Gail Miller gave students advice based on her decades of business experience and philanthropy, saying one of the guiding principles of the Larry H. Miller Company has been "be a student, be a teacher, be a leader."

10 hours ago

Pro-Palestinian protestors gathered outside the Jon M. Huntsman Center....

Emma Keddington

Pro-Palestinian protestors gather outside University of Utah commencement, move to county jail

Dozens of pro-Palestinian protestors gathered outside the University of Utah's commencement ceremony, moved to the Salt Lake County Jail.

11 hours ago

This image from video released by the U.S. Army, shows a frame from a haunting new video, released ...

LOLITA C. BALDOR Associated Press

New Army video aims to lure recruits for psychological operations

A haunting new video is the latest effort by the U.S. Army to lure soldiers to some of its more secretive units.

11 hours ago

Sponsored Articles

a doctor putting her hand on the chest of her patient...

Intermountain Health

Intermountain nurse-midwives launch new gynecology access clinic

An access clinic launched by Intermountain nurse-midwives provides women with comprehensive gynecology care.

Young couple hugging while a realtor in a suit hands them keys in a new home...

Utah Association of Realtors

Buying a home this spring? Avoid these 5 costly pitfalls

By avoiding these pitfalls when buying a home this spring, you can ensure your investment will be long-lasting and secure.

a person dressed up as a nordic viking in a dragon boat resembling the bear lake monster...

Bear Lake Convention and Visitors Bureau

The Legend of the Bear Lake Monster

The Bear Lake monster has captivated people in the region for centuries, with tales that range from the believable to the bizarre.

...

Live Nation Concerts

All the artists coming to Utah First Credit Union Amphitheatre (formerly USANA Amp) this summer

Summer concerts are more than just entertainment; they’re a celebration of life, love, and connection.

Mother and cute toddler child in a little fancy wooden cottage, reading a book, drinking tea and en...

Visit Bear Lake

How to find the best winter lodging in Bear Lake, Utah

Winter lodging in Bear Lake can be more limited than in the summer, but with some careful planning you can easily book your next winter trip.

Happy family in winter clothing at the ski resort, winter time, watching at mountains in front of t...

Visit Bear Lake

Ski more for less: Affordable ski resorts near Bear Lake, Utah

Plan your perfect ski getaway in Bear Lake this winter, with pristine slopes, affordable tickets, and breathtaking scenery.

NSA finds major security flaw in Windows 10, free fix issued