Microsoft Warns Windows PCs Also Vulnerable to 'Freak' Attacks Hundreds of millions of Windows PC users are vulnerable to attacks exploiting the recently uncovered security vulnerability, Microsoft says.

By Reuters

This story originally appeared on Reuters

insider.windows.com

Hundreds of millions of Windows PC users are vulnerable to attacks exploiting the recently uncovered "Freak" security vulnerability, which was initially believed to only threaten mobile devices and Mac computers, Microsoft Corp warned.

News of the vulnerability surfaced on Tuesday when a group of nine security experts disclosed that ubiquitous Internet encryption technology could make devices running Apple Inc's iOS and Mac operating systems, along with Google Inc's Android browser vulnerable to cyber attacks.

Microsoft released a security advisory on Thursday warning customers that their PCs were also vulnerable to the "Freak" vulnerability.

The weakness could allow attacks on PCs that connect with Web servers configured to use encryption technology intentionally weakened to comply with U.S. government regulations banning exports of the strongest encryption.

If hackers are successful, they could spy on communications as well as infect PCs with malicious software, the researchers who uncovered the threat said on Tuesday.

The Washington Post on Tuesday reported that whitehouse.gov and fbi.gov were among the sites vulnerable to these attacks, but that the government had secured them.

Security experts said the vulnerability was relatively difficult to exploit because hackers would need to use hours of computer time to crack the encryption before launching an attack.

"I don't think this is a terribly big issue, but only because you have to have many ducks in a row," said Ivan Ristic, director of engineering for cybersecurity firm Qualys Inc.

That includes finding a vulnerable web server, breaking the key, finding a vulnerable PC or mobile device, then gaining access to that device.

Microsoft advised system administrators to employ a workaround to disable settings on Windows servers that allow use of the weaker encryption. It said it was investigating the threat and had not yet developed a security update that would automatically protect Windows PC users from the threat.

Apple said it had developed a software update to address the vulnerability, which would be pushed out to customers next week.

Google said it had also developed a patch, which it provided to partners that make and distribute Android devices.

"Freak" stands for Factoring RSA-EXPORT Keys.

(Reporting by Jim Finkle; Editing by Jonathan Oatis and Richard Chang)

Wavy Line

Editor's Pick

A Leader's Most Powerful Tool Is Executive Capital. Here's What It Is — and How to Earn It.
Lock
One Man's Casual Side Hustle Became an International Phenomenon — And It's on Track to See $15 Million in Revenue This Year
Lock
3 Reasons to Keep Posting on LinkedIn, Even If Nobody Is Engaging With You
Why a Strong Chief Financial Officer Is Crucial for Your Franchise — and What to Look for When Hiring One

Related Topics

Starting a Business

5 Tips For Launching a Business While Keeping Your Day Job

Launching a business while holding down a 9-to-5 is no small feat. It's a common path for aspiring entrepreneurs, but it's not without its challenges.

Money & Finance

7 Ways to Make Extra Income Even With a Full-Time Job

Want to make more money? Real estate investing, Amazon ecommerce and the sharing economy are waiting for you.

Leadership

Why Time Management Doesn't Work — And How My Team Doubled Their Productivity Once I Started Doing This Instead

Time management is killing your productivity – here's why and what you need to do to increase your productivity instead.

Business News

The Virgin Islands Want to Serve Elon Musk a Subpoena, But They Can't Find Him

Government officials would like to talk to Tesla's owner as part of an investigation into the Jeffrey Epstein case.

Fundraising

Working Remote? These Are the Biggest Dos and Don'ts of Video Conferencing

As more and more businesses go remote, these are ways to be more effective and efficient on conference calls.