Saturday, October 12, 2024

Microsoft Blames Security Info-Sharing Program for Attack Code Leak

Datamation content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

Computerworld: Someone has leaked sample exploit code to hackers, and Microsoft isn’t happy about it.

The story begins in March of 2011 when Italian security researcher Luigi Auriemma found a security vulnerability in Windows Remote Desktop Protocol. Auriemma passed the information on to HP TippingPoint’s Zero Day Initiative, a bug bounty program. The HP group then created a sample exploit, which they passed on to Microsoft. Microsoft shared the exploit with members of the Microsoft Active Protection Program (MAPP), security vendors who have signed a strict non-disclosure agreement. However, it appears that someone violated that agreement because Auriemma found the exploit code in use on a Chinese website.

According to Microsoft’s Yunsun Wee,”Microsoft is actively investigating the disclosure of these details and will take the necessary actions to protect customers and ensure that confidential information we share is protected pursuant to our contracts and program requirements.”

Subscribe to Data Insider

Learn the latest news and best practices about data science, big data analytics, artificial intelligence, data security, and more.

Similar articles

Get the Free Newsletter!

Subscribe to Data Insider for top news, trends & analysis

Latest Articles