You may have heard something about an emergency patch for Windows 10. Apparently, it was a huge deal. Now, we know why. The US National Security Agency (NSA) discovered a serious flaw in Windows 10 that could expose users to surveillance or serious data breaches, according to the Washington Post. That was backed by Krebs on Security, which reported that the NSA confirmed that it did find a major vulnerability that it passed on to Microsoft.
In the past, the NSA might have kept the security hole to itself, using it to spy on adversaries. If you wanted to know where WannaCry and EternalBlue came from, there you go. Windows 10 vulnerabilities were discovered and exploited by the NSA for years. The agency developed hacking tools to exploit those holes, but some of them were uncovered and released by a suspected Russian hacking group called Shadow Brokers. EternalBlue is still used to this day on unpatched systems for ransomware, theft and other types of attacks.
The NSA confirmed that the vulnerability affects Windows 10 and Windows Server 2016. It said that it flagged the dangerous bug because it “makes trust vulnerable.” However, it wouldn’t say when it found the flaw and declined to discuss it further until Microsoft released a patch. So, you know they were up to something.
According to Krebs, the vulnerability was found in a Windows component called crypt32.dll, which handles “certificate and cryptographic messaging functions,” according to Microsoft. An exploit in that area could affect authentication on Windows desktops and servers, sensitive data on Microsoft’s Internet Explorer and Edge browsers and many third-party applications. Hackers could also use it to spoof digital signatures, making malware look like a legitimate app.
A software patch was released earlier to critical Windows 10 clients including the US military and managers of key internet infrastructure. Microsoft has since released updates for all customers, urging them to install them “as quickly as practical.” As Krebs notes, the company rated the exploitability of the vulnerability as 1 — the second most severe in Microsoft’s rating system. Again, the company confirmed it has not yet been exploited, but is still a major security issue.
So, after all that jargon, the basic takeaway from this piece is to update your Windows 10 desktop or laptop as soon as humanly possible.