
The IBMers , from IBM X-Force Research, were instrumental in demonstrating the bug to Microsoft in May, which is currently rated 9.3/10. The public announcement came after the release of a software update that could close the backdoor, provided that everyone, including server administrators, quickly install the critical patch. According to IBM researchers, the bug could allow remote code execution, allowing an attacker to take complete control of a computer. The patch that closes the backdoor was released in the critical update of the operating system for November . Although it was not known whether any attacks should now be attributed to the security gap in Microsoft's software for secure data transfer (Microsoft Secure Channel), experts are sounding the alarm for IT departments to install the patch, since the bug also exists in Windows Server versions and the security of websites that are required to handle encrypted data is at risk. Moreover, the publication of the event does not exclude, on the contrary, increases the possibility of attacks now targeting systems that have not installed the critical update.
The security flaw is considered as serious as the Heartbleed bug that was also discovered in 2014: HeartBleed: The heart of the Internet is bleeding, does it concern you?
