Tribune Online
  • Home
  • News
  • Business
  • Columns
  • Editorial
  • Entertainment
  • Politics
  • Health
  • Sports
  • Opinions
  • Women
No Result
View All Result
  • Home
  • News
  • Business
  • Columns
  • Editorial
  • Entertainment
  • Politics
  • Health
  • Sports
  • Opinions
  • Women
No Result
View All Result
Tribune Online
No Result
View All Result

Hackers exploited Word flaw for months while Microsoft investigated

by Tribune Online
April 27, 2017
in World News
Reading Time: 3 mins read
A A
Remote work 'll define post-COVID-19 business landscape, 1O,000 African start-ups to benefit from Microsoft initiatives in five years, Microsoft boosts small-midsize businesses with new working tool, Microsoft guides employers on keys to unlocking hybrid work success, Microsoft supports digital transformation, 50% of jobs require digital skills, Partnership with Nigerian govt, Jobs, Microsoft, journalists

To understand why it is so difficult to defend computers from even moderately capable hackers, consider the case of the security flaw officially known as CVE-2017-0199.

The bug was unusually dangerous but of a common genre: it was in Microsoft software, could allow a hacker to seize control of a personal computer with little trace, and was fixed April 11 in Microsoft’s regular monthly security update.

But it had traveled a rocky, nine-month journey from discovery to resolution, which cyber security experts say is an unusually long time.

Google’s security researchers, for example, give vendors just 90 days’ warning before publishing flaws they find. Microsoft Corp (MSFT.O) declined to say how long it usually takes to patch a flaw.

While Microsoft investigated, hackers found the flaw and manipulated the software to spy on unknown Russian speakers, possibly in Ukraine.

And a group of thieves used it to bolster their efforts to steal from millions of online bank accounts in Australia and other countries.

Related News

Spring of Life partners New Horizons to produce 20 Microsoft Technology Associates

‘Consumers instrumental to digital transformation sustainability’

The Definitive Guide: Microsoft AZ-304 and becoming a Microsoft Architect Designer

Those conclusions and other details emerged from interviews with researchers at cyber security firms who studied the events and analyzed versions of the attack code.

Microsoft confirmed the sequence of events.

The tale began last July, when Ryan Hanson, a 2010 Idaho State University graduate and consultant at boutique security firm Optiv Inc in Boise, found a weakness in the way that Microsoft Word processes documents from another format. That allowed him to insert a link to a malicious program that would take control of a computer.

Hanson spent some months combining his find with other flaws to make it more deadly, he said on Twitter. Then in October he told Microsoft. The company often pays a modest bounty of a few thousands dollars for the identification of security risks.

Soon after that point six months ago, Microsoft could have fixed the problem, the company acknowledged. But it was not that simple. A quick change in the settings on Word by customers would do the trick, but if Microsoft notified customers about the bug and the recommended changes, it would also be telling hackers about how to break in.


Alternatively, Microsoft could have created a patch that would be distributed as part of its monthly software updates. But the company did not patch immediately and instead dug deeper. It was not aware that anyone was using Hanson’s method, and it wanted to be sure it had a comprehensive solution.

“We performed an investigation to identify other potentially similar methods and ensure that our fix addresses [sic] more than just the issue reported,” Microsoft said through a spokesman, who answered emailed questions on the condition of anonymity. “This was a complex investigation.”

The saga shows that Microsoft’s progress on security issues, as well as that of the software industry as a whole, remains uneven in an era when the stakes are growing dramatically.

The United States has accused Russia of hacking political party emails to interfere in the 2016 presidential election, a charge Russia denies, while shadowy hacker groups opposed to the U.S. government have been publishing hacking tools used by the Central Intelligence Agency and National Security Agency.

 



Tags: HackersMicrosoft
ShareTweetSendShareShare

Related News

Syria Turkey earthquake
Latest News

Atleast 1600 dead in Syria, Turkey earthquake

February 6, 2023
Will Smith- Bad boys 4
Entertainment

Will Smith, Martin Lawrence announce new ‘Bad Boys’ movie series

February 1, 2023
decriminalize hard drugs, Iron drug use disorders , Drugs, heartburn drug, COVID-19
Latest News

Addictions: British Columbia becomes first province in Canada to decriminalize hard drugs

February 1, 2023

Discussion about this post

Most Read

  • Tems wins as Burna Boy loses Grammy Awards
    Tems wins as Burna Boy loses Grammy Awards
  • Tinubu vs Atiku: North in focus
    Tinubu vs Atiku: North in focus
  • Naira Redesign: Father Mbaka blasts Buhari, says 'Nigerians are suffering' under his watch
    Naira Redesign: Father Mbaka blasts Buhari, says 'Nigerians are suffering' under his watch
  • 2023: It is time for the North to complete 14 years of ruling — Dogara
    2023: It is time for the North to complete 14 years of ruling — Dogara
  • 2023: Why elements in the Villa are sabotaging Tinubu ― Ayiri Emami
    2023: Why elements in the Villa are sabotaging Tinubu ― Ayiri Emami
  • Elections: Nation's security forces on red alert over scarcity of fuel, new naira notes
    Elections: Nation's security forces on red alert over scarcity of fuel, new naira notes
  • Academics are as important as relationships, friendships  —Oluwakorede Adedeji, Unilorin Pharmacy best graduating student
    Academics are as important as relationships, friendships —Oluwakorede Adedeji, Unilorin Pharmacy best graduating student
  • Tinubu makes U-turn, postpones Ibadan rally indefinitely
    Tinubu makes U-turn, postpones Ibadan rally indefinitely
  • Again, court sends EFCC boss to Kuje prison for contempt
    Again, court sends EFCC boss to Kuje prison for contempt
  • BBTitans: I used 'Kayanmata' to attract senators ―​​ Nana opens up
    BBTitans: I used 'Kayanmata' to attract senators ―​​ Nana opens up

Subscribe to e-Paper

E-Vending, e paper, pdf, e-paper, Tribune

Frontpage Today

EDITORIAL

Editorial
Opinion
Letters

BUSINESS

Capital Market
Money Market
Economy

ENTERTAINMENT

Friday Treat
Entertainment
Razzmattaz

REGIONS

South West
Niger Delta
Arewa

RELIGION

Tribune Church
Church News
Muslim Sermon
Eye of Islam
Islamic News
COLUMNS

Anike's Diary
Aplomb
Ask The Doctor
Autoclinic With The Mechanic
Awo's Thought
Borderless
Crucial Moment
Empowered For Life
Festus Adebayo's Flickers
Financewise
Gibbers
Intimacy
Language & Style
Leaders' Forum
Leadership & Management
Lynx Eye
Monday Lines
Mum & Child
Natural Health
Notes from Atlanta with Farooq Kperogi
On The Lord's Day
PENtagon
Political Panorama
Veritatem With Obadiah Mailafia
Voice of Courage
Whatsapp Conversation
You and Eye
Your Life Counts

WOMEN

Xquisite
Xquisite Food
Xquisite Style
Wondrous World of Women

MORE

Business Coach
Education
Event Digest
Crime & Court
Do It Yourself
Ecoscope
Property & Environment
Energy
Maritime
Aviation
Brands & Marketing
Agriculture
Info Tech
Labour
Leadership & Management
Achievers
Arewa Live
Arts & Culture
Arts & Reviews
Campus Beat
Politics
Health News
  • About Us
  • Contact us
  • Disclaimer
  • Privacy
  • Tribune Advertisement Rates

© 2023 Tribune Online, an online publication of African Newspapers of Nigeria Plc. All Rights Reserved.

No Result
View All Result
  • Home
  • News
  • Business
  • Columns
  • Editorial
  • Entertainment
  • Politics
  • Health
  • Sports
  • Opinions
  • Women

© 2023 Tribune Online, an online publication of African Newspapers of Nigeria Plc. All Rights Reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist