Microsoft has just patched a critical security hole in Windows 10 discovered in 2018
The vulnerability is codenamed CVE-2020-1464 and described by Microsoft as an impersonation flaw in the way Windows authenticates digital signature files. An attacker who successfully exploits this vulnerability can bypass security features and download malicious, malicious files into the system.
However, two security researchers Tal Be'ery and Peleg Hadar revealed that the vulnerability was reported to Microsoft two years ago, on August 18, 2020. At that time, Microsoft announced it would not patch the vulnerability.
VirusTotal discovered that the Java file contained malicious code in 2018, according to security researcher Bernardo Quintero. back that they won't patch this flaw.
In January 2019, Quintero also announced more details about CVE-2020-1464. After checking the Java file for malicious code, he discovered that it was an MSI file appended to a Java file. Although it has been modified, Windows still considers this file to have a valid digital signature from Google, which you can see in the photo below.
Because some security solutions use digital signatures to determine whether the file has launch permissions, hackers can use this technique to bypass the security system. After that, they take control and cause unpredictable damage to the victim.
After updating the patch for CVE-2020-1464, Windows 10 will remove the digital signature of MSI files if they are turned into a Java file containing malicious code. You can compare the properties of a Java file containing malicious code on Windows 10 1909 and Windows 10 2004 (right) in the picture below.
Hacker can also add other files to MSI file however only Java file can be used to deploy malicious code.
It is still not clear why Microsoft refused to patch the vulnerability in 2018 but proceeded to fix it after two years. Microsoft also does not recognize Quintero as the first to discover this vulnerability.
You should read it
- Microsoft rewards $ 250,000 for any talent that discovers the new Meltdown and Specter vulnerabilities
- Microsoft fixes 8 critical vulnerabilities
- Detects 'long-standing' security vulnerabilities in Microsoft Office
- Summary: All new Windows 10 features are announced by Microsoft at Build 2020
- Microsoft patched 6 zero-day vulnerabilities in Windows 10
- Microsoft released a patch for 75 critical vulnerabilities on Windows 7 / 8.1 / 10, asking users to install
- Microsoft patched drive-by errors in March
- How to check if the computer has serious Windows 10 vulnerabilities
May be interested
- Will the new trojan appear?last wednesday, a japanese-based security firm said it had discovered a trojan that exploited windows's image-processing security hole - just one day after microsoft gave it. issued b
- Discovering the new serious security vulnerability of Bitcoin can cause the whole system to crashrecently, developers have discovered a critical security hole of bitcoin, even more dangerous than a 51% attack, which could cause the entire system of this cryptocurrency to collapse. .
- Microsoft silently patched the KRACK WPA2 security holewhile other vendors are trying to release an update to patch the krack attack vulnerability yesterday, microsoft quietly corrected the problem in a patch last tuesday.
- Critical vulnerabilities discovered in Framework Electron, Skype, Slack, Twitch and a series of affected appsthe framework of a variety of popular desktop applications such as skype, slack, signal, twitch ... appears a serious security hole. it is important that this vulnerability only affects windows.
- A pre-installed application on Windows 10 has a major security holetrend micro's zero day initiative (zdi) security researchers have discovered a new vulnerability in the paint 3d tool that comes pre-installed with windows 10.
- Google revealed a critical flaw in Qualcomm's Adreno GPUthe google project zero team has publicly revealed a security hole that exists in the adreno gpu integrated on the snapdragon chip.
- Mozilla patches a vulnerability in Firefox that helps hackers gain admin rights of Windowsmozilla has just released a security update to patch a critical security vulnerability that allows hackers to escalate privileges on windows computers. this critical security flaw has been patched in the recently released version of firefox 97.
- Security vulnerability discovered on Windows 7, affecting millions of usersa security hole has just been discovered in windows 7 that can affect millions of users. security researchers recently found a local privilege vulnerability in windows 7 that could affect millions of windows users who haven't updated since this release.
- Immediately fix critical vulnerabilities in Windows NTLM security protocolresearchers on firewall preempt behavior have discovered two new vulnerabilities in windows ntlm security protocols. let's see what those holes are and how serious it is!
- Microsoft fixes a serious security holeas announced last week, microsoft has released two updates for two security holes that are classified as serious