PDA

View Full Version : Microsoft Revokes Trust In 28 of Its Own Certificates



wraggster
July 11th, 2012, 20:30
"In the wake of the Flame malware attack, which involved the use of a fraudulent Microsoft digital certificate, the software giant has reviewed its certificates, found nearly 30 that aren't as secure as the company would like (https://threatpost.com/en_us/blogs/microsoft-revokes-trust-28-its-own-certificates-071012), and revoked them. Microsoft also released its new updater for certificates as a critical update for Windows Vista and later versions as part of today's July Patch Tuesday. Microsoft has not said exactly what the now-untrusted certificates were used for, but company officials said there were a total of 28 certificates affected by the move (http://technet.microsoft.com/en-us/security/advisory/2728973). However, the company said it was confident none of them had been compromised or used maliciously. The move to revoke trust in these certificates is a direct result of the investigation into the Flame malware and how the attackers were able to forge a Microsoft certificate and then use it to impersonate a Windows Update server
http://it.slashdot.org/story/12/07/10/2122220/microsoft-revokes-trust-in-28-of-its-own-certificates