Hiding in Plain Site: 20 Year Old Windows Exploit Patched…

by

August 20, 2019

In the words of the immortal Charlie Brown; good grief.

A Windows exploit that’s been around for almost 20 years was finally patched last week.

Apparently every single version of Windows has had this vulnerability.  The vulnerability is a part of a legacy protocol called CTF. CTF is a part of the Windows Text Services Framework.  CTF is used to control things like keyboard layout, text input methods, etc.

The flaw allows a would-be attacker to compromise an app, like the Notes app for example, and then launch other programs that run CTF. That could potentially include your internet browser.

The flaw was discovered by Tavis Ormandy, a researcher who’s a part of Google’s Project Zero. Ormandy’s been in the news for discovering other major flaws.

Ormandy first reached out to Microsoft regarding the vulnerability in May but the software giant seemed to ignore his findings. After waiting nearly three months for a response Ormandy finally released his findings on his own blog. You can read what he said in depth here.

As I said above, Microsoft did finally release an update that fixes the problem. If you haven’t patched your systems yet we recommend doing so.

 

Carl Keyser is the Content Manager at Integris.

Keep reading

How Microsoft 365 management is a game-changer for law firms

How Microsoft 365 management is a game-changer for law firms

Law firms are investing in technologies for operational efficiency and to become more competitive in a crowded market. Increasingly, managed service providers (MSPs) are helping law firms with Microsoft 365 management so that law firms can operate more efficiently and...

Anchor Links Test

This is a test of using anchor links to form a TOC. Table of Contents: Header One Header Two Proin finibus euismod maximus. Vivamus non volutpat nisi. Nullam ac porta diam. Nullam id tortor a ante mattis elementum. Integer vel lorem id velit pharetra venenatis a ut...

Is DeepSeek Safe for My Company’s Systems?

Is DeepSeek Safe for My Company’s Systems?

China’s new DeepSeek AI engine Has Ushered in a New Era of Fast-Turn, Low-Cost AI Tools. But Are the Risks Worth the Rewards for US Companies? Key Takeaways: China's DeepSeek has been hailed as the nimble new competitor to US large language AI models—an alternative...