The Broadband Guide
SG
search advanced

Flame virus spread through rogue Microsoft security certificates

2012-06-04 09:50 by
Tags: ,

 

Microsoft released an emergency Windows update on Sunday after revealing that one of its trusted digital signatures was being abused to certify the validity of the Flame malware that has infected computers in Iran and other Middle Eastern Countries.

The digital certificate issue, stemming from a problem with Microsoft's Terminal Server Licensing Service cryptography algorithm, could make malware appear as if it was a genuine Microsoft software product. Microsoft's modern operating systems, like Windows 7 and Vista, use methods (like UAC) to present a software publishers details upon installation.

"We have discovered through our analysis that some components of the malware have been signed by certificates that allow software to appear as if it was produced by Microsoft. We identified that an older cryptography algorithm could be exploited and then be used to sign code as if it originated from Microsoft. Specifically, our Terminal Server Licensing Service, which allowed customers to authorize Remote Desktop services in their enterprise, used that older algorithm and provided certificates with the ability to sign code, thus permitting code to be signed as if it came from Microsoft," said Mike Reavey, a senior director of the Microsoft Trustworthy Computing.

Windows users are urged to install the new KB2718704 patch. If Automatic Updates are enabled, the patch should automatically install. If not, users can open Windows Update on their PC and manually install it.

Read more -here-

 

  Post your review/comments
    rate:
   avg:
News Glossary of Terms FAQs Polls Cool Links SpeedGuide Teams SG Premium Services SG Gear Store
Registry Tweaks Broadband Tools Downloads/Patches Broadband Hardware SG Ports Database Security Default Passwords User Stories
Broadband Routers Wireless Firewalls / VPNs Software Hardware User Reviews
Broadband Security Editorials General User Articles Quick Reference
Broadband Forums General Discussions
Advertising Awards Link to us Server Statistics Helping SG About