Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Microsoft alerted about new Windows flaw by NSA

Microsoft alerted about new Windows flaw by NSA

Kareem Anderson Kareem Anderson
January 14, 2020
2 min read

With various versions of Windows occupying a billion devices worldwide, Microsoft’s premier operating system paints a rather large target on its back for smaller B2B security firms looking to stay ahead of nefarious parties, while also finding itself in the crosshairs of much larger agencies who might want to weaponize exploits for future data and surveillance collection.

The United States National Security Agency recently chose the former option as it alerted Microsoft about a Windows flaw that could put millions of users in danger of breach or surveillance hack. For obvious reasons, the details of the exploit are relatively vague, but according to the Washington Post, the vulnerability is essentially a mistake in computer code that specifically targets users of Microsoft’s latest Windows 10 operating system. By leveraging Microsoft and Adobe’s Code-signing sync engine, the NSA found an error in the Windows code that normally verifies legitimate signatures but could now ultimately allow hackers to install ransomware or spyware on Windows 10 PCs if exploited.

More specifically,

“The discovery has been likened to a slightly less severe version of the Microsoft flaw that the NSA once weaponized by creating a hacking tool dubbed EternalBlue, which one former agency hack said was like “fishing with dynamite.”

As a bit of a refresher, EternalBlue exploits a vulnerability in Microsoft’s implementation of the Server Message Block (SMB) protocol. The vulnerability exists because the SMB version 1 (SMBv1) protocol in various versions of Windows mishandles specially crafted packets from remote attackers, allowing them to execute arbitrary code on the target computer. The NSA used and, arguably abused the exploit right up until it became widely distributed online five years after they discovered it. The NSA ultimately alerted Microsoft in 2017 and a patch followed in early 2017, but only months before three other major cyberattacks were credited using the tool.

Fortunately, the NSA isn’t holding on to this one and giving it room to breathe like EternalBlue. Instead, by alerting Microsoft quickly, the NSA appears to be exhibiting a shift in prioritization of security and surveillance, for now at least. While Microsoft has had no comment on the matter, the NSA seems confident that the company will have a patch issued Tuesday to address the exploit, at which point Microsoft and the NSA can declare that “it has seen no active exploitation of the flaw.”

The discovery of the exploit comes as Microsoft ends security support for Windows 7 and attempts to shift consumers and businesses still using the soon-to-be vulnerable OS, over to Windows 10.

Share This Post:

Tags: EternalBlue | Microsoft | NSA | Vulnerability | Windows 10 | Windows 7
Share this article:
Tags:
EternalBlue Microsoft NSA Vulnerability Windows 10 Windows 7
Previous Article PC sales grew from the first time since 2011 last year, according to market research Next Article Xbox team is “hard at work on E3” while PlayStation skips it again

Related Articles

New Rowhammer Attacks Turn NVIDIA GPUs Into a System-Level Security Risk

April 4, 2026
Titan Army U275M could push gaming monitors to 1060Hz with dual-mode display

Titan Army U275M could push gaming monitors to 1060Hz with dual-mode display

April 4, 2026

New Intel Leak Shows Bigger Nova Lake Desktop CPU with 44 Cores

April 4, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • New Rowhammer Attacks Turn NVIDIA GPUs Into a System-Level Security Risk
  • Titan Army U275M could push gaming monitors to 1060Hz with dual-mode display
  • New Intel Leak Shows Bigger Nova Lake Desktop CPU with 44 Cores
  • NVIDIA Neural Rendering Reduces VRAM From 6.5GB to 970MB Without Losing Detail
  • H.264 Licensing Fees Rise to $4.5 Million for Streaming Platforms in 2026

Recent Comments

  1. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  2. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • New Rowhammer Attacks Turn NVIDIA GPUs Into a System-Level Security Risk
  • Titan Army U275M could push gaming monitors to 1060Hz with dual-mode display
  • New Intel Leak Shows Bigger Nova Lake Desktop CPU with 44 Cores
  • NVIDIA Neural Rendering Reduces VRAM From 6.5GB to 970MB Without Losing Detail
  • H.264 Licensing Fees Rise to $4.5 Million for Streaming Platforms in 2026

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy