Tech content trusted by users in North America and around the world
6,727 Reviews & Articles | 46,188 News Posts
TRENDING NOW: AMD's dual Fiji chip spotted as Radeon R9 Gemini, is this the Fury X2?

Microsoft may have leaked code capable of attacking critical Windows bug

Microsoft could be responsible for leaking code capable of exploiting a Windows bug.
| Hacking & Security News | Posted: Mar 16, 2012 11:29 pm

No, I'm not trying to use scare tactics. No, I don't want you to rip out your link to the internet. I just want you to beware: Microsoft may have had a hand in leaking executable code that was used in a proof-of-concept (PoC). The data packet that was used was the same that Luigi Auriemma, an Italian security researcher, discovered and reported way back in May of 2011. Last Tuesday, Microsoft updated all flavors of Windows to patch the critical RDP vulnerability. Both Microsoft, and I, strongly recommend that you update and patch all of your machines running Windows.




Auriemma has stated:


In short it seems written by Microsoft for [its] internal tests and was leaked probably during its distribution to their 'partners' for the creation of antivirus signatures and so on. The other possible scenario is [that] a Microsoft employee was [the] direct or indirect source of the leak. [A] hacker intrusion looks the less probable scenario at the moment.


Other researchers have said that the RDP proof-of-concept was unreliable, and only crashed Windows. The existing code, however, would be a good starting point for a successful exploit, they noted. "Microsoft has spread the potential starting point for an unauthenticated kernel-level worm,"Auriemma charged. "Weren't they here to protect the users?" The Microsoft patch MS12-020 is available via Windows Update and Windows Server Update. It is highly recommended to install the patch as soon as possible, because, which bills itself as a place to "Hire the best hackers," is offering a reward to the first working exploit of the bug.


Related Tags

Got an opinion on this news? Post a comment below!
Subscribe to our Newsletter

Latest News Posts

View More News Posts

Forum Activity

View More Forum Posts

Press Releases

View More Press Releases