Critical Windows Crypto Flaw Prompts Urgent Pre-Patch Tuesday Fixes
Microsoft prepares an emergency fix for a severe vulnerability in a core Windows cryptographic component that allows attackers to spoof digital signatures. The company quietly provides early patches to key infrastructure operators under strict non-disclosure agreements.
Microsoft releases a software update to fix an extraordinarily serious security vulnerability in a core cryptographic component present in all versions of Windows. The company quietly ships a patch for the bug to branches of the U.S. military and other high-value targets that manage key Internet infrastructure, requiring these organizations to sign agreements that prevent them from disclosing details of the flaw.
The vulnerability resides in crypt32.dll, a Windows module that handles certificate and cryptographic messaging functions in the CryptoAPI. A critical flaw in this component has wide-ranging security implications for Windows functions, including user authentication, the protection of sensitive data in Internet Explorer and Edge, and various third-party applications.
Because this component is introduced more than 20 years ago in Windows NT 4.0, all versions of Windows face potential risk. Most concerning is the ability of attackers to abuse the flaw to spoof digital software signatures, which makes malware appear as a benign program produced by a legitimate software company.