Hiding in Plain Site: 20 Year Old Windows Exploit Patched…

by

August 20, 2019

In the words of the immortal Charlie Brown; good grief.

A Windows exploit that’s been around for almost 20 years was finally patched last week.

Apparently every single version of Windows has had this vulnerability.  The vulnerability is a part of a legacy protocol called CTF. CTF is a part of the Windows Text Services Framework.  CTF is used to control things like keyboard layout, text input methods, etc.

The flaw allows a would-be attacker to compromise an app, like the Notes app for example, and then launch other programs that run CTF. That could potentially include your internet browser.

The flaw was discovered by Tavis Ormandy, a researcher who’s a part of Google’s Project Zero. Ormandy’s been in the news for discovering other major flaws.

Ormandy first reached out to Microsoft regarding the vulnerability in May but the software giant seemed to ignore his findings. After waiting nearly three months for a response Ormandy finally released his findings on his own blog. You can read what he said in depth here.

As I said above, Microsoft did finally release an update that fixes the problem. If you haven’t patched your systems yet we recommend doing so.

 

Carl Keyser is the Content Manager at Integris.

Keep reading

Where Can I Find Reviews of Managed IT Firms?

Where Can I Find Reviews of Managed IT Firms?

Where Can I Find Reviews of Managed IT Firms? The Quick Take Businesses looking for a reputable managed IT services provider have several options for finding the best third-party rankings and reviews, including: Third party review sites—such as industry-favorite,...

Strong Cybersecurity Postures: How to Unleash their Power

Strong Cybersecurity Postures: How to Unleash their Power

In the vast digital landscape where virtual dragons and sneaky trolls roam a strong cybersecurity posture has never been more important. Imagine a band of modern-day knights led by our protagonist, Alex. Armed with a trusty laptop and a cup of coffee, Alex navigates...