Rogue Certificate Being Used In Wild To Compromise Windows
Coincidentally I’ve just posted about how broken the Certificate Authority system is and here’s an advisory (Microsoft Security Advisory (2718704)) not 5 minutes later from Microsoft talking about an ‘Unauthorized Digital Certificate’ being used in the wild against users.
There don’t seem to be any details but it seems that someone out there has either hacked or otherwise gotten their hands on a Microsoft certificate and they’re using it to perform attacks on users.
There isn’t much to do about this one without more details given. Just update Windows ASAP and you should be fine.
Just another example as to why the entire CA system is broken.
Update
It turns out that this certificate is used by the Flame malware, which would possibly explain why it was reportedly able to infect fully patched Windows 7 computers.
Components of the Flame malware were signed with a certificate that chained up to the Microsoft Enforced Licensing Intermediate PCA certificate authority, and ultimately, to the Microsoft Root Authority. This code-signing certificate came by way of the Terminal Server Licensing Service that we operate to issue certificates to customers for ancillary PKI-based functions in their enterprise. Such a certificate could (without this update being applied) also allow attackers to sign code that validates as having been produced by Microsoft.
The implications of this being that Flame could bypass default Windows 7 UAC or potentially attack the system in other ways (depending on what the cert can do.)
blog comments powered by Disqus