Moneycontrol PRO
Black Friday Sale
Black Friday Sale
HomeNewsTechnologyWindows-powered data centres still vulnerable to CryptoAPI bug, says Akamai

Windows-powered data centres still vulnerable to CryptoAPI bug, says Akamai

CryptoAPI helps developers secure their Windows apps cryptographically

January 28, 2023 / 16:51 IST
(Representative Image)

A bug in the Windows CryptoAPI is still unpatched on most data centre systems. Security researchers from Akamai said that the bug was discovered and fixed by Microsoft in August 2022, but 99 percent of Windows-based data centres have still not been patched.

The CryptoAPI allows developers to secure their Windows apps cryptographically, but a bug in the API allows malicious actors to sign certificates in a way that tricks Windows into believing they are legitimate.

Also Read: Microsoft digital certificates used to sign malware by ransomware group Cuba 

If an organisation relies on CryptoAPI for authentication, attackers can craft a fake certificate that will trick the API into validating it. It allows bad actors to pretend to be another organisation or system, allowing them to take control over the victim's computer.

Microsoft issued a patch for the bug in August 2022, but disclosed it only in October. It appears many organisations have still not applied the patch to their data centres.

The bug was first disclosed to Microsoft by the US National Security Agency (NSA) and UK's National Cyber Security Center (NCSC).

Also Read: Another EternalBlue-like flaw threatens Windows PCs

"We found that fewer than one percent of visible devices in data centres are patched, rendering the rest unprotected from exploitation of this vulnerability," Akamai security researchers Tomer Peled and Yoni Rozenshein told The Register.

"The attack flow is twofold. The first phase requires taking a legitimate certificate, modifying it, and serving the modified version to the victim. The second phase involves creating a new certificate whose MD5 collides with the modified legitimate certificate, and using the new certificate to spoof the identity of the original certificate’s subject," wrote the duo in a blog post.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Moneycontrol News
first published: Jan 28, 2023 04:50 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347