Microsoft updates Windows to combat VeriSign glitch
Computerworld - Microsoft Corp. today said it has completed a promised software update for all of its Windows operating system releases dating back to 1995 as part of an effort to combat a pair of fraudulent digital certificates that were mistakenly issued by VeriSign Inc.
Microsoft also plans to send e-mail messages announcing the availability of the update to more than 130,000 users who subscribe to its security mailing list. The update, which can be downloaded from Microsoft's Web site, is meant to protect Windows users from security threats posed by the invalid digital certificates issued to an imposter claiming to be a Microsoft employee.
The problem first came to light last week, when both Microsoft and Mountain View, Calif.-based VeriSign posted warnings about the fraudulent certificates (see story). Microsoft yesterday issued a new version of its advisory with detailed information about the software update.
Digital certificates are used to prove the origin and authenticity of software programs and data on the Internet, a key requirement for users who are downloading patches or software updates. VeriSign and other certificate issuers generate and digitally sign such certificates after first verifying the identity of the individual or organization that submitted the request.
But in this case, the two certificates issued by VeriSign in late January incorrectly list Microsoft as the owner. The danger, according to Microsoft, is that the fraudulent certificates "are of a type that can be used to digitally sign programs, including ActiveX controls and Office macros" -- a capability that a malicious attacker could use to try to trick users into thinking that unsafe software programs are bona fide Microsoft products.
"Because of the risk this issue poses, Microsoft has taken the unusual step of producing an update for every Windows operating system produced since 1995, regardless of whether it's normally supported or not," the software vendor said in the updated advisory. Users of all releases ranging from Windows 95 to the beta-test version of the upcoming Windows XP should install the update, Microsoft added.
The update should help ensure that software code "signed" by the two fraudulent certificates is recognized as invalid by users, the company said. After installing the update, users who try to install a program that has been authenticated by either certificate should see a warning dialogue that says the certificate has been revoked.
It would still be possible for users to override the warning and run the program, but Microsoft said it would "strongly recommend" against doing so. "The fact that a certificate has been revoked



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Forrester Total Economic Impact (TEI) Case Study - Oracle
- In this paper, Forrester Consulting examines the total economic impact and potential return on investment (ROI) realized by three Enterprise organizations as they...
- The Hidden Truth About Virtualizing Business-Critical Applications
- This IDG whitepaper highlights key findings based on the Quickpoll Survey conducted with more than 300 Enterprise and Commercial IT decision makers worldwide...
- Top 10 Myths About Virtualizing Business-Critical Applications
- Even though virtualization has brought positive change to enterprise IT over the last decade, some skepticism remains about how valuable virtualization can be...
- Enterprise Java Applications on VMware: Unix to Linux Migration Guide
- This guide focuses on key considerations for IT Architects who are in the process of migrating Java applications from UNIX to Linux as...
- Virtualizing Tier 1 Applications: A Critical Step on the Journey Toward the Private Cloud
- This IDC white paper explains how much of the Enterprise IT community is at a crossroads in extending their journey to the private... All Applications White Papers
- Live Webcast
Banish Poor Application Performance: Eliminate Business Disruptions, Increase End User Productivity - End User Experience, 30-Min Webinar
Wed. Feb. 22nd ~ 11 AM ET
Are you ready to gain the proactive ability to rapidly respond... - Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
- Discover the Benefits of Virtualization for Federal Applications
- Want to say goodbye to missed SLAs? VMware can help you virtualize mission-critical applications such as Oracle, MS Exchange and SharePoint to achieve...
- Reduce Application Lifecycle Management Costs with VMware ThinApp
- Traditional desktop application deployment and management is a time-consuming and costly endeavor for IT. From development to deployment, including help desk support, the... All Applications Webcasts