Microsoft fixes FREAK vulnerability in Patch Tuesday update

Microsoft has issued critical patches for Windows, Internet Explorer and Office

With the latest Patch Tuesday release, Microsoft is fixing the FREAK vulnerability that could help attackers intercept secured network communications.

The security bulletin is one of 14 that Microsoft issued Tuesday, five of which are marked critical, meaning administrators should apply them as quickly as possible.

The bulletins address vulnerabilities residing in both the consumer and server editions of Windows, Internet Explorer, Office, SharePoint Server and Exchange Server.

Discovered earlier this month, FREAK (Factoring attack on RSA-EXPORT Keys) provides a way for an attacker to intercept SSL-encrypted traffic encrypted by SSL (Secure Sockets Layer) as it moves between clients and servers.

An attacker could use the flaw to secretly access and even alter communications between two parties, said Amol Sarwate, director of engineering at security firm Qualys.

While the FREAK flaw itself resides in SSL, Microsoft has fixed the SSL implementations in its own software through MS15-031.

The critical bulletins for both Explorer (MS15-018) and Office (MS15-022) address flaws that would let an attacker take remote control of a machine, Sarwate said.

An attacker could use the vulnerabilities, for instance, to plant a malicious program onto a machine, by tricking a user into opening either an infected Web page in the case of Explorer, or an infected document in Office. "It basically turns the user's machine into the attacker's machine," Sarwate said.

Although not ranked as critical, MS15-026 should be examined by administrators who oversee Exchange servers, Sarwate said. The vulnerabilities affect Exchange's Outlook Web Access (OWA), which provides a way for users to check email with a browser. A user could be fooled into clicking on a maliciously crafted e-mail link that directs them to the OWA site, and then extends the user's access privileges on that machine to the attacker.

Another bulletin, MS15-030, highlights the importance of properly securing remote access connections to a server. The vulnerability resides in Microsoft Remote Desktop Protocol (RDP), which could be used to cripple a server with a denial of service (DoS) attack.

Administrators like using RDP because it provides an easy way to log into a remote machine, but if they are doing this they should employ additional security measures, such as using a virtual private network connection, said Wolfgang Kandek, Qualys chief technology officer. Keeping a port open for RDP traffic coming directly in from the Internet provides another attack surface. At the minimum, RDP users should apply this patch.

Joab Jackson covers enterprise software and general technology breaking news for The IDG News Service. Follow Joab on Twitter at @Joab_Jackson. Joab's e-mail address is

Join the CSO newsletter!

Error: Please check your email address.

Tags Microsoftsecuritypatch management

More about IDGMicrosoftNewsQualysRSA

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Joab Jackson

Latest Videos

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

  • 150x50

    IDG Live Webinar:The right collaboration strategy will help your business take flight

    Speakers - Mike Harris, Engineering Services Manager, Jetstar - Christopher Johnson, IT Director APAC, 20th Century Fox - Brent Maxwell, Director of Information Systems, THE ICONIC - IDG MC/Moderator Anthony Caruana

    Play Video

More videos

Blog Posts

Market Place