FILE PHOTO: The Microsoft logo is pictured ahead of the Mobile World Congress in Barcelona, Spain February 24, 2019. REUTERS/Sergio Perez
(Reuters) – Microsoft Corp said on Tuesday it will roll out a security fix that cybersecurity experts expect will correct a highly dangerous weakness in its popular Windows operating system.
Microsoft Senior Director Jeff Jones said in a statement that the company does not discuss details ahead of an update. But cybersecurity circles have been abuzz here for most of the day in anticipation that the fix repairs flaws in how the operating system authenticates and secures data.
The Washington Post reported on Tuesday that the National Security Agency discovered the flaw in recent weeks and alerted Microsoft to the problem.
NSA declined to comment ahead of a phone briefing on Tuesday about the vulnerability.
The NSA had previously come under criticism after it took advantage of vulnerabilities in Microsoft products to deploy hacking tools against adversaries and kept the Redmond, Washington-based company in the dark about it for years. When one of those tools was dramatically leaked to the internet by a group calling itself ShadowBrokers, it was deployed against targets around the globe by hackers of all stripes.
In the most dramatic case, a group used the tool to unleash a massive malware outbreak dubbed WannaCry in 2017. The data-wiping worm wrought global havoc, affecting what Europol estimated was some 200,000 computers in more than 150 countries. (Read story here )
Reporting by Raphael Satter; Editing by Richard Chang