A "fatal" security flaw that has existed in all versions of Windows since Windows 95, that is, for 19 years, has just been made public. The catalytic contribution was made by IBMers, from the IBM X-Force Research department, who demonstrated the bug to Microsoft in May, which is currently assigned a severity rating of 9.3/10.
The public announcement came after Microsoft released a software update that could close the backdoor, provided that everyone, including server administrators, rushes to install the critical patch.
According to IBM researchers, the bug could allow remote code execution that could allow an attacker to take complete control of a computer. The patch that closes the backdoor was released in the operating system's critical update for November.
Although it is not known whether any attacks should now be attributed to the security gap in Microsoft's software for secure data transfer (Microsoft Secure Channel), experts are sounding the alarm for IT departments to install the patch, since the bug also exists in Windows Server and the security of websites that are required to handle encrypted data is at risk. Moreover, the disclosure of the event does not exclude, on the contrary, the possibility of attacks now targeting systems that have not installed the critical update.
The security flaw is considered as serious as the Heartbleed bug that was also discovered in 2014: HeartBleed: The heart of the Internet is bleeding, does it concern you?
Source: tech.in.gr

