Security Advisor

Microsoft Echoes Security Issue

Microsoft released a security advisory this week warning about an issue that could cause VPN passwords to be stolen, thanks to the work of a couple of hackers.

While the flaw wasn't discovered by Microsoft's army of coders, developers and security issues, the info came from the inventors of the hacking method during a presentation at last month's Defcon security conference.

So why didn't Microsoft warn its users of this flaw after the reveal? Well, like any responsible software company, it had to take some time to investigate the issue itself (and to monitor if anyone was using the exploit in the wild).

Good news is that it looks like nobody is currently using the exploit in the wild. Bad news is all Microsoft can do is repeat the findings that came out last month (and provide info on a workaround). There currently isn't a security update, and Microsoft did not announce that one is on its way.

About the Author

Chris Paoli is the site producer for Redmondmag.com and MCPmag.com.

Featured

  • Microsoft Releases Windows 10 Version 1909

    Microsoft on Tuesday announced the release of Windows 10 version 1909, a new operating system product that's also known as the "Windows 10 November 2019 Update."

  • November Microsoft Security Bundle Addresses 75 Vulnerabilities

    Of that number, 13 vulnerabilities are rated "Critical" to patch, while 62 vulnerabilities are deemed "Important."

  • The Future of Office 365 Pricing

    With a raft of new Office 365 features in the pipeline, Microsoft also seems ready to change the way it bills its subscribers. Will it replicate Azure's pay-per-use model, or will it look like something else entirely?

  • Microsoft Offers 1 Year of Free Windows 7 Extended Security Updates to E5 Licensees

    Microsoft is offering one year of free support under its Extended Security Updates program to Windows 7 users if their organizations have E5 licensing.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.