Business Standard

Hackers exploited Word flaw for months while Microsoft probed

The bug was unusually dangerous but of a common genre: It was in Microsoft software

Microsoft
Premium

Photo: Shutterstock

Joseph Menn | Reuters
To understand why it is so difficult to defend computers from even moderately capable hackers, consider the case of the security flaw officially known as CVE-2017-0199.

The bug was unusually dangerous but of a common genre: It was in Microsoft software, could allow a hacker to seize control of a personal computer with little trace, and was fixed April 11 in Microsoft's regular monthly security update.

But it had travelled a rocky, nine-month journey from discovery to resolution, which cyber security experts say is an unusually long time.

Google's security researchers, for example, give vendors just 90 days' warning before publishing flaws they

What you get on BS Premium?

  • Unlock 30+ premium stories daily hand-picked by our editors, across devices on browser and app.
  • Pick your 5 favourite companies, get a daily email with all news updates on them.
  • Full access to our intuitive epaper - clip, save, share articles from any device; newspaper archives from 2006.
  • Preferential invites to Business Standard events.
  • Curated newsletters on markets, personal finance, policy & politics, start-ups, technology, and more.
VIEW ALL FAQs

Need More Information - write to us at assist@bsmail.in