Microsoft revokes certificates in Flame malware

By Juha Saarinen on Jun 5, 2012 8:18 AM
Filed under Security

Windows 8 up first.

Microsoft has issued emergency updates for all versions of Windows to revoke three of its own certificates used to sign the recently discovered Flame malware.

The updates, which include release previews for Windows 8 and Windows Server 2012, sought to prevent future use of the certificates to "spoof content, perform phishing attacks, or perform man-in-the-middle attacks" on operating system updates.

The certificates were initially issued for users to authorise Remote Desktop services in their enterprises

According to a Microsoft security advisory, the creators of the Flame malware – discovered last week but thought to be in action for some time – exploited a bug in the Terminal Services licensing certificate authority allowing them to generate fake certificates which made the malware code appear trustworthy.

Microsoft security engineer Jonathan Ness said an older cryptography method used to sign and issue certificates for trusted software could be exploited for this use.

Remember to sign up to our CRN Channelwire bulletin to stay connected with the latest channel news and analysis from Australia and around the world.

Ness said components of the Flame malware were signed with a certificate that ultimately linked up to the Microsoft Root Authority. Such a certificates would allow attackers to sign code and make it appear as if it's been produced by Microsoft rather than a third party.

The malware spread through removable media and exploited a since-patched Microsoft printer hole – the same tapped by Stuxnet.

It contained a backdoor and trojan and had worm-like features, allowing it to replicate in a local network and on removable media if it is commanded to do so.

F-Secure's chief research office Mikko Hypponen said in a blog post that access to bogus Microsoft certificates were the "holy grail of malware writers".

"This has now happened," he said.

Despite the exploit, Hypponen said the certificate flaw had not been used by its writers to conduct financial attacks. Instead, he said it was most likely a Western intelligence agency looking to conduct targetted attacks instead.

 
Follow us on Facebook and Twitter
 

Copyright © iTnews.com.au . All rights reserved.

Microsoft revokes certificates in Flame malware
 
 
 
 
 
Top Stories
 
Oakton to sell Dimension Data cloud
Strategic relationship.
 
Data#3 warns of grim full year
Uncertainty in Queensland.
 
Sign up to receive CRN email bulletins
   FOLLOW US...
Latest Comments
Polls
Is your business doing as well now as it was at this time last year?


   |   View results
Yes
  32%
 
No
  54%
 
The same
  14%
TOTAL VOTES: 486

Vote now
CRN Magazine

Issue: 316 | July 2013

CRN Magazine looks in-depth at the emerging issues and developments for the channel, and provides insight, analysis and strategic information to help resellers better run their businesses.