dcsimg

Microsoft Blames Security Info-Sharing Program for Attack Code Leak

Download the authoritative guide: Cloud Computing 2018: Using the Cloud to Transform Your Business

SHARE
Share it on Twitter  
Share it on Facebook  
Share it on Google+
Share it on Linked in  
Email  

Computerworld: Someone has leaked sample exploit code to hackers, and Microsoft isn't happy about it.

The story begins in March of 2011 when Italian security researcher Luigi Auriemma found a security vulnerability in Windows Remote Desktop Protocol. Auriemma passed the information on to HP TippingPoint's Zero Day Initiative, a bug bounty program. The HP group then created a sample exploit, which they passed on to Microsoft. Microsoft shared the exploit with members of the Microsoft Active Protection Program (MAPP), security vendors who have signed a strict non-disclosure agreement. However, it appears that someone violated that agreement because Auriemma found the exploit code in use on a Chinese website.

According to Microsoft's Yunsun Wee,"Microsoft is actively investigating the disclosure of these details and will take the necessary actions to protect customers and ensure that confidential information we share is protected pursuant to our contracts and program requirements."

Submit a Comment

Loading Comments...

NewsletterDATAMATION DAILY NEWSLETTER

SUBSCRIBE TO OUR IT MANAGEMENT NEWSLETTER