Microsoft may have leaked code capable of attacking critical Windows bug

Microsoft could be responsible for leaking code capable of exploiting a Windows bug.

Published
Updated
1 minute & 4 seconds read time

No, I'm not trying to use scare tactics. No, I don't want you to rip out your link to the internet. I just want you to beware: Microsoft may have had a hand in leaking executable code that was used in a proof-of-concept (PoC). The data packet that was used was the same that Luigi Auriemma, an Italian security researcher, discovered and reported way back in May of 2011. Last Tuesday, Microsoft updated all flavors of Windows to patch the critical RDP vulnerability. Both Microsoft, and I, strongly recommend that you update and patch all of your machines running Windows.

Microsoft may have leaked code capable of attacking critical Windows bug | TweakTown.com

Auriemma has stated:

In short it seems written by Microsoft for [its] internal tests and was leaked probably during its distribution to their 'partners' for the creation of antivirus signatures and so on. The other possible scenario is [that] a Microsoft employee was [the] direct or indirect source of the leak. [A] hacker intrusion looks the less probable scenario at the moment.

Other researchers have said that the RDP proof-of-concept was unreliable, and only crashed Windows. The existing code, however, would be a good starting point for a successful exploit, they noted. "Microsoft has spread the potential starting point for an unauthenticated kernel-level worm,"Auriemma charged. "Weren't they here to protect the users?" The Microsoft patch MS12-020 is available via Windows Update and Windows Server Update. It is highly recommended to install the patch as soon as possible, because Gun.io, which bills itself as a place to "Hire the best hackers," is offering a reward to the first working exploit of the bug.

NEWS SOURCE:computerworld.com

Trace is a starving college student studying Computer Science. He has a love of the English language and an addiction for new technology and speculation. When he's not writing, studying, or going to class, he can be found on the soccer pitch, both playing and coaching, or on the mountain snowboarding.

Newsletter Subscription

Related Tags