Microsoft: SSL flaw is in OS not IE

Microsoft said Wednesday that the SSL flaw recently uncovered by an independent researcher is in multiple versions of the Windows operating system and not its Internet Explorer Web browser.

Company officials added that the flaw also is not in Microsoft's CryptoAPI (CAPI), which would leave a number of applications and Windows services vulnerable, not just IE.

Microsoft said it is working on patches for Windows 98, ME, NT4, 2000 and XP. It would not say when the patches would be available.

"This SSL flaw has been described as an [Internet Explorer] problem but it is a Windows issue. It's in the crypto of the operating system so we have to patch the OS," said Scott Culp manager of the Microsoft Security Response Center. "IE is a consumer of those crypto services."

He said it is an "implementation problem in the way SSL certificates are processed where information is not available in the certificate or it is available in two places and there is a conflict."

Culp said the flaw does not lie within CAPI and that it lies in code that performs validation of SSL certificate chains, meaning the hierarchy of trust that cascades from certificate authorities such as VeriSign Inc. The OS must be patched because IE does not have its own cryptography code and must rely on the OS for that service, he said.

Konqueror.org was able to patch its open source Konqueror Web browser, which had the same SSL flaw as IE, in under 90 minutes because it uses its own built-in certification verification library.

Microsoft officials said it makes sense for the OS to provide cryptographic services to any application that needs it instead of each application having to include it's own cryptographic technology.

But Culp said the SSL flaw does not effect any other application outside IE and that it is a client side issue only.

"That's interesting, I'll have to do some more testing," said Mike Benham, an independent researcher who first reported the SSL flaw. "Possibly this is a second can of worms."

Benham reported on Tuesday that Internet Explorer had a security flaw that undermines the security provided by Secure Socket Layer (SSL), a standard for securing online transactions and electronic commerce.

The flaw opens up a vulnerability that is called a man-in-the-middle attack, where the attacker can hijack an SSL session and decrypt messages that could contain credit card numbers or social security numbers.

The IDG News Service contributed to this report.

Join the newsletter!

Or
Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

John Fontana

Computerworld
Show Comments

Essentials

Mobile

Victorinox Werks Professional Executive 17 Laptop Case

Learn more >

Exec

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?