In this 2010 photo, a display for Microsoft’s Windows 7 is shown at the National Retail Federation’s convention in New York. (AP Photo/Mark Lennihan, File)

In this 2010 photo, a display for Microsoft’s Windows 7 is shown at the National Retail Federation’s convention in New York. (AP Photo/Mark Lennihan, File)

NSA discovers security flaw in Windows, Microsoft issues fix

The software company said it has not seen any evidence of exploitation by hackers.

By Matt O’Brien / Associated Press

The National Security Agency has discovered a major security flaw in Microsoft’s Windows 10 operating system that could let hackers intercept seemingly secure communications.

But rather than exploit the flaw for its own intelligence needs, the NSA tipped off Microsoft so that it can fix the system for everyone.

Microsoft released a free software patch to fix the flaw Tuesday and credited the intelligence agency for discovering it. The company said it has not seen any evidence that hackers have used the technique.

Amit Yoran, CEO of security firm Tenable, said it is “exceptionally rare if not unprecedented” for the U.S. government to share its discovery of such a critical vulnerability with a company.

Yoran, who was a founding director of the Department of Homeland Security’s computer emergency readiness team, urged all organizations to prioritize patching their systems quickly.

An advisory sent by the NSA on Tuesday said “the consequences of not patching the vulnerability are severe and widespread.”

Microsoft said an attacker could exploit the vulnerability by spoofing a code-signing certificate so it looked like a file came from a trusted source.

“The user would have no way of knowing the file was malicious, because the digital signature would appear to be from a trusted provider,” the company said.

If successfully exploited, an attacker would have been able to conduct “man-in-the-middle attacks” and decrypt confidential information it intercepts on user connections, the company said.

Some computers will get the fix automatically, if they have the automatic update option turned on. Others can get it manually by going to Windows Update in the computer’s settings.

Microsoft typically releases security and other updates once a month and waited until Tuesday to disclose the flaw and the NSA’s involvement. Microsoft and the NSA both declined to say when the agency privately notified the company.

The agency shared the vulnerability with Microsoft “quickly and responsibly,” Neal Ziring, technical director of the NSA’s cybersecurity directorate, said in a blog post Tuesday.

Priscilla Moriuchi, who retired from the NSA in 2017 after running its East Asia and Pacific operations, said this is a good example of the “constructive role” that the NSA can play in improving global information security. Moriuchi, now an analyst at the U.S. cybersecurity firm Recorded Future, said it’s likely a reflection of changes made in 2017 to how the U.S. determines whether to disclose a major vulnerability or exploit it for intelligence purposes.

The revamping of what’s known as the “Vulnerability Equities Process” put more emphasis on disclosing vulnerabilities whenever possible to protect core internet systems and the U.S. economy and general public.

Those changes happened after a mysterious group calling itself the “Shadow Brokers” released a trove of high-level hacking tools stolen from the NSA, forcing companies including Microsoft to repair their systems. The U.S. believes that North Korea and Russia were able to capitalize on those stolen hacking tools to unleash devastating global cyberattacks.

Talk to us

More in Herald Business Journal

Alderwood mall is ready for the governor’s green light

The Lynnwood shopping center, closed since March 24, could reopen in June. But expect changes.

Boeing cutting more than 12,000 jobs with layoffs, buyouts

The company said it will lay off 6,770 workers this week, and another 5,520 are taking buyouts.

Firm accused of violating eviction ban agrees to restitution

About 1,450 tenants, including some in Marysville, will receive rent refunds or direct payments.

Snohomish County seeks to enter second phase of reopening

The variance request will go to the state if approved by the Board of Health and the County Council.

Boeing workers cope with the virus threat as layoffs loom

Five weeks after they returned to work, Boeing workers say measures inside the plants are mostly working.

Texan comes to defend Snohomish outlaw barber cutting hair

Bob Martin is defying orders to close. The man he calls his attorney didn’t go to law school.

Hundreds of masked guests line up as Tulalip casinos reopen

Tulalip Resort Casino and Quil Ceda Creek opened the doors on Tuesday after a two-month closure.

Worst jobless rate in the state: Snohomish County at 20.2%

In April, 91,383 were unemployed in the county. The aerospace sector was hit especially hard.

Small business relief effort inundated with 850 applications

The economy in and around Everett has struggled amid fallen revenues and uncertainty about the future.

Most Read