Business Standard

Hackers exploited Word flaw for months while Microsoft probed

- JOSEPH MENN

To understand why it is so difficult to defend computers from even moderately capable hackers, consider the case of the security flaw officially known as CVE-2017-0199.

The bug was unusually dangerous but of a common genre: It was in Microsoft software, could allow a hacker to seize control of a personal computer with little trace, and was fixed April 11 in Microsoft's regular monthly security update.

But it had travelled a rocky, ninemonth journey from discovery to resolution, which cyber security experts say is an unusually long time.

Google's security researcher­s, for example, give vendors just 90 days' warning before publishing flaws they find. Microsoft declined to say how long it usually takes to patch a flaw.

While Microsoft investigat­ed, hackers found the flaw and manipulate­d the software to spy on unknown Russian speakers, possibly in Ukraine.

And a group of thieves used it to bolster their efforts to steal from millions of online bank accounts in Australia and other countries.

Those conclusion­s and other details emerged from interviews with researcher­s at cyber security firms who studied the events and analysed versions of the attack code.

Microsoft confirmed the sequence of events. The tale began last July, when Ryan Hanson, a 2010 Idaho State University graduate and consultant at boutique security firm Optiv Inc in Boise, found a weakness in the way that Microsoft Word processes documents from another format. That allowed him to insert a link to a malicious program that would take control of a computer.

Hanson spent some months combining his find with other flaws to make it more deadly, he said on Twitter. Then in October he told Microsoft. The company often pays a modest bounty of a few thousands dollars for the identifica­tion of security risks.

Soon after that point six months ago, Microsoft could have fixed the problem, the company acknowledg­ed. But it was not that simple.

 ??  ??

Newspapers in English

Newspapers from India