HomeNewsTechnologyWindows-powered data centres still vulnerable to CryptoAPI bug, says Akamai

Windows-powered data centres still vulnerable to CryptoAPI bug, says Akamai

CryptoAPI helps developers secure their Windows apps cryptographically

January 28, 2023 / 16:51 IST
Story continues below Advertisement
(Representative Image)
(Representative Image)

A bug in the Windows CryptoAPI is still unpatched on most data centre systems. Security researchers from Akamai said that the bug was discovered and fixed by Microsoft in August 2022, but 99 percent of Windows-based data centres have still not been patched.

The CryptoAPI allows developers to secure their Windows apps cryptographically, but a bug in the API allows malicious actors to sign certificates in a way that tricks Windows into believing they are legitimate.

Story continues below Advertisement

Also Read: Microsoft digital certificates used to sign malware by ransomware group Cuba 

If an organisation relies on CryptoAPI for authentication, attackers can craft a fake certificate that will trick the API into validating it. It allows bad actors to pretend to be another organisation or system, allowing them to take control over the victim's computer.