In this 2010 photo, a display for Microsoft’s Windows 7 is shown at the National Retail Federation’s convention in New York. (AP Photo/Mark Lennihan, File)

In this 2010 photo, a display for Microsoft’s Windows 7 is shown at the National Retail Federation’s convention in New York. (AP Photo/Mark Lennihan, File)

NSA discovers security flaw in Windows, Microsoft issues fix

The software company said it has not seen any evidence of exploitation by hackers.

  • By MATT O’BRIEN AP Technology Writer
  • Tuesday, January 14, 2020 1:04pm
  • BusinessNorthwest

By Matt O’Brien / Associated Press

The National Security Agency has discovered a major security flaw in Microsoft’s Windows 10 operating system that could let hackers intercept seemingly secure communications.

But rather than exploit the flaw for its own intelligence needs, the NSA tipped off Microsoft so that it can fix the system for everyone.

Microsoft released a free software patch to fix the flaw Tuesday and credited the intelligence agency for discovering it. The company said it has not seen any evidence that hackers have used the technique.

Amit Yoran, CEO of security firm Tenable, said it is “exceptionally rare if not unprecedented” for the U.S. government to share its discovery of such a critical vulnerability with a company.

Yoran, who was a founding director of the Department of Homeland Security’s computer emergency readiness team, urged all organizations to prioritize patching their systems quickly.

An advisory sent by the NSA on Tuesday said “the consequences of not patching the vulnerability are severe and widespread.”

Microsoft said an attacker could exploit the vulnerability by spoofing a code-signing certificate so it looked like a file came from a trusted source.

“The user would have no way of knowing the file was malicious, because the digital signature would appear to be from a trusted provider,” the company said.

If successfully exploited, an attacker would have been able to conduct “man-in-the-middle attacks” and decrypt confidential information it intercepts on user connections, the company said.

Some computers will get the fix automatically, if they have the automatic update option turned on. Others can get it manually by going to Windows Update in the computer’s settings.

Microsoft typically releases security and other updates once a month and waited until Tuesday to disclose the flaw and the NSA’s involvement. Microsoft and the NSA both declined to say when the agency privately notified the company.

The agency shared the vulnerability with Microsoft “quickly and responsibly,” Neal Ziring, technical director of the NSA’s cybersecurity directorate, said in a blog post Tuesday.

Priscilla Moriuchi, who retired from the NSA in 2017 after running its East Asia and Pacific operations, said this is a good example of the “constructive role” that the NSA can play in improving global information security. Moriuchi, now an analyst at the U.S. cybersecurity firm Recorded Future, said it’s likely a reflection of changes made in 2017 to how the U.S. determines whether to disclose a major vulnerability or exploit it for intelligence purposes.

The revamping of what’s known as the “Vulnerability Equities Process” put more emphasis on disclosing vulnerabilities whenever possible to protect core internet systems and the U.S. economy and general public.

Those changes happened after a mysterious group calling itself the “Shadow Brokers” released a trove of high-level hacking tools stolen from the NSA, forcing companies including Microsoft to repair their systems. The U.S. believes that North Korea and Russia were able to capitalize on those stolen hacking tools to unleash devastating global cyberattacks.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

Judi Ramsey, owner of Artisans, inside her business on Sept. 22, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Artisans PNW allows public to buy works of 100 artists

Combo coffee, art gallery, bookshop aims to build business in Everett.

Helion's 6th fusion prototype, Trenta, on display on Tuesday, July 9, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Everett-based Helion receives approval to build fusion power plant

The plant is to be based in Chelan County and will power Microsoft data centers.

The Port of Everett’s new Director of Seaport Operations Tim Ryker on Oct. 14, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Port of Everett names new chief of seaport operations

Tim Ryker replaced longtime Chief Operating Officer Carl Wollebek, who retired.

The Lynnwood City Council listens to a presentation on the development plan for the Lynnwood Event Center during a city council meeting on Oct. 13, 2025 in Lynnwood, Washington. (Olivia Vanni / The Herald)
Lynnwood City Council approves development of ‘The District’

The initial vision calls for a downtown hub offering a mix of retail, events, restaurants and residential options.

Customers walk in and out of Fred Meyer along Evergreen Way on Monday, Oct. 31, 2022 in Everett, Washington. (Olivia Vanni / The Herald)
Closure of Fred Meyer leads Everett to consider solutions for vacant retail properties

One proposal would penalize landlords who don’t rent to new tenants after a store closes.

Everly Finch, 7, looks inside an enclosure at the Reptile Zoo on Aug. 19, 2025 in Monroe, Washington. (Olivia Vanni / The Herald)
Monroe’s Reptile Zoo to stay open

Roadside zoo owner reverses decision to close after attendance surge.

Trade group bus tour makes two stops in Everett

The tour aimed to highlight the contributions of Washington manufacturers.

Downtown Everett lumberyard closes after 75 years

Downtown Everett lumber yard to close after 75 years.

Paper covers the windows and doors of a recently closed Starbucks at the corner of Highway 99 and 220th Street SW on Oct. 1, 2025 in Edmonds, Washington. (Olivia Vanni / The Herald)
Starbucks shutters at least six locations in Snohomish County

The closures in Lynnwood, Edmonds, Mill Creek and Bothell come as Starbucks CEO Brian Niccol attempts to reverse declining sales.

Keesha Laws, right, with mom and co-owner Tana Baumler, left, behind the bar top inside The Maltby Cafe on Sept. 29, 2025 in Snohomish, Washington. (Olivia Vanni / The Herald)
A change in ownership won’t change The Maltby Cafe

The new co-owner says she will stick with what has been a winning formula.

Holly Burkett-Pohland inside her store Burketts on Sept. 24, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Burkett’s survives in downtown thanks to regular customers

Unique clothing and gift store enters 48th year in Everett.

A person walks past the freshly painted exterior of the Everett Historic Theatre on Sept. 24, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Historic Everett Theatre reopens with a new look and a new owner

After a three-month closure, the venue’s new owner aims to keep the building as a cultural hub for Everett.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.