The NSA discovered the flaw in the digital signatures Microsoft uses to help prevent malware from being downloaded on a computer. If exploited, the flaw would allow hackers to download malware on the computer without being detected.
Microsoft released a patch for the vulnerability Jan. 14 and is recommending those using Windows 10 update their operating systems immediately. The Department of Homeland Security also issued an emergency directive Jan. 14, telling federal agencies to update their systems immediately.
For users who have automatic updates, the patch for the vulnerability has been installed, confirmed Jeff Jones, a Microsoft senior director, in a statement to WSJ.
More articles on cybersecurity:
Health systems should update computer systems in wake of Iran tensions, H-ISAC says
3 cybersecurity predictions for 2020
Former NYC hospital employee pleads guilty to hacking coworkers’ emails