Microsoft Aims to Harden Windows Update to Fight "Flame"
June 6, 2012 2:24 PM
Fighting copycats variants of a piece of escaped government malware is no easy task
In the Middle East, information technology experts are grappling with a very persistent piece of malware dubbed Flame. Flame is slightly older than the much-discussed Stuxnet worm. Stuxnet is a researcher-named escaped variant of "The Bug", a series of worms used in
an elaborate U.S. and Israeli cyber-sabotage program
code-named "Olympics Games". That effort was aimed (successfully) at
destroying Iranian nuclear weapons fuel enrichment centrifuges
I. Flame Forces Patch
Likewise, Flame is suspected to be written by the U.S. to target Iranian nuclear efforts or possibly Al Qaeda. However, its goals appeared to be aimed at reconnaissance rather than sabotage.
Regardless of the purpose, it is less subtle than "The Bug" variants, and while confined largely to the Middle East has been a top cleanup priority for Microsoft Corp. (
Rooting out the Flame worm is a top priority for Microsoft. [Image Source: Krishnan Vasuvedan]
Microsoft Security Response Center
blog, Microsoft laid out its plans to slay Flame and harden its
Windows Update (WU) process
Microsoft reports that Flame spread itself by using cryptography weaknesses in an older version of Microsoft's certification process. That allowed the software to pose as trusted signed software from Microsoft and install without warning the user.
Flame has narrowly targeted the Middle East, particularly Iran. [Image Source: Kapersky Labs]
In its blog, Microsoft warns, "As many reports assert, Flame has been used in highly sophisticated and targeted attacks and, as a result, the vast majority of customers are not at risk.... That said, our investigation has discovered some techniques used by this malware that could also be leveraged by less sophisticated attackers to launch more widespread attacks."
The blog goes on to reveal the company's current fix to the problem, outlining:
First, today we released a
outlining steps our customers can take to block software signed by these unauthorized certificates.
• Second, we released an update that automatically takes this step for our customers.
• Third, the Terminal Server Licensing Service no longer issues certificates that allow code to be signed.
II. Malicious Updates are a Harder Fix
But Flame illustrated deeper underlying security issues for Windows, in that Microsoft feared that copycats could tamper with the Windows Update process to prevent its potential removal. Some malware authors have been finding ways to literally "turn off" Windows Update, preventing fixes and patches from reach affected machines. And as Microsoft notes in its blog update, sophisticated attackers could even leverage Windows Update to deliver malware masquerading as signed Microsoft updates.
Malware writers could potentially disguise their malfeasant wares as Windows Updates.
The company writes that it plans on "hardening" WU, commenting:
To increase protection for customers, the next action of our mitigation strategy is to further harden Windows Update as a defense-in-depth precaution. We will begin this update following broad adoption of Security Advisory 2718704 in order not to interfere with that update’s worldwide deployment. We will provide more information on the timing of the additional hardening to Windows Update in the near future.
In other words, while sophisticated state-written malware like Flame and Stuxnet may have created headaches, both diplomatically and technologically, they served as a "full disclosure" warning of sorts to Microsoft. These attacks have given it the knowledge and motivation to patch some gaping holes that might have otherwise gone unnoticed and quietly exploited for some time -- or at least that's the glass half-full way of looking at the situation.
"There is a single light of science, and to brighten it anywhere is to brighten it everywhere." -- Isaac Asimov
NYT: President Obama Authorized Stuxnet Attack on Iran
June 1, 2012, 1:54 PM
Windows 8 Looks to Ditch the "Zombie" Security Restarts of Windows 7
November 15, 2011, 4:38 PM
Israel Suspected in Worm Sabotage of Iran's First Nuclear Plant
September 27, 2010, 10:45 AM
Samsung S8 and S8 Plus: On Sale April 21 at Major Wireless Dealers
March 30, 2017, 7:35 AM
Are You in the Market for Earphones?
March 24, 2017, 7:35 AM
Samsung Galaxy S8, Rumored Launch Date!
March 18, 2017, 6:45 AM
How about Leica Cameras
March 13, 2017, 6:30 AM
Nokia has ditched this camera technology in its new smartphones
March 7, 2017, 8:45 AM
A Baseball Cap With Camera
March 3, 2017, 7:00 AM
Most Popular Articles
Are You in the Market for Earphones?
March 24, 2017, 7:35 AM
OnePlus 3T – 5.5” Optic AMOLED and Dash Charging Technology
March 23, 2017, 8:45 AM
Gigabyte GA-Z170X-Gaming G1 – Intel Thunderbolt 3 Certified Motherboard
March 9, 2017, 6:25 AM
Huawei P8 Lite 2017 – Android 7 Nougat Smartphone with Octa-Core Processor
March 8, 2017, 7:03 AM
Acer Swift 3 – Ultra Thin Laptop in an All-Aluminum Shell
March 25, 2017, 7:40 AM
Latest Blog Posts
Uber Technologies Inc Driverless Car hit by Human-driver
Mar 30, 2017, 8:00 AM
Android Creator and New Bezel-less Smartphone
Mar 29, 2017, 10:28 AM
More Apps From Google
Mar 28, 2017, 7:15 AM
Are you thinking of performance and speed? Intel claims:
Mar 25, 2017, 7:45 AM
Apple buys an automation app called Workflow. The deal was completed today and brings the app along with its developers.
Mar 23, 2017, 7:35 AM
Apple Announces new color for iPhones and iPads
Mar 22, 2017, 7:45 AM
Instagram: You Can Now Save Live Videos For Later
Mar 21, 2017, 7:49 AM
Samsung Galaxy S8 to Get New Color Scheme
Mar 20, 2017, 7:45 AM
What else to worry about?
Mar 17, 2017, 6:45 AM
Icon of the Day: Intel/ NVIDIA or Mobileye
Mar 16, 2017, 6:15 AM
JUST IN - Twitter Hijacked : High-Profile Account Accesses
Mar 15, 2017, 7:07 AM
Mar 14, 2017, 7:30 AM
News and Tips
Mar 13, 2017, 6:30 AM
iPhone 8 – May Not Get Curved Screen
Mar 11, 2017, 8:00 AM
California paves way to self-driving car tests without humans
Mar 11, 2017, 7:18 AM
Smart Machines V hackers
Mar 10, 2017, 7:00 AM
Uber Can Resume Autonomous Car Testing in California
Mar 9, 2017, 6:50 AM
Mar 8, 2017, 7:09 AM
Mar 7, 2017, 8:45 AM
World news 3-6
Mar 6, 2017, 5:40 AM
Mar 4, 2017, 7:40 AM
Mixed News of the Day
Mar 4, 2017, 6:32 AM
More Blog Posts
Copyright 2017 DailyTech LLC. -
Terms, Conditions & Privacy Information