
In an official Security Advisory, Microsoft has revealed that it's Windows operating Systems are vulnerable to a FREAK SSL/TLS Flaw. The FREAK flaw is a loophole that allows hackers to initiate man-in-the-middle attacks on connections like Sockets Layer(SSL) and Transport Layer Security(TLS). These two security layers use outdated encryption to cipher.
" Microsoft is aware of a security feature bypass vulnerability in Secure Channel (Schannel) that affects all supported releases of Microsoft Windows. Our investigation has verified that the vulnerability could allow an attacker to force the downgrading of the cipher suites used in an SSL/TLS connection on a Windows client system. The vulnerability facilitates exploitation of the publicly disclosed FREAK technique, which is an industry-wide issue that is not specific to Windows operating systems. " reported Microsoft in an official advisory.
It should be remembered that a few days ago, we had reported about the FREAK attacks on Apple and Google using man-in-the-middle technique and now Microsoft is their latest victim.
Mitigation
Microsoft has claimed to be working with their partners under it's "Microsoft Active Protections Program(MAPP)". Under this program Microsoft aims to share information that they can use to provide broader protections to customers. Microsoft has also reassured customers about protection & security. Microsoft has also issued a workout for users to deactivate the RSA keys exchange ciphers which makes room for FREAK attacks by altering the SSL Cipher Suite in the Group Policy Object Editor.
Microsoft appropriately took the stance to announce a mitigation system to be followed, helping customers, upon successful completion of the investigation.
"This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs", Microsoft added.
The Microsoft has provided a list of versions affected the FREAK attacks which include almost every version of Operating System from Windows Server 2003 to Windows Server 2012 and Windows 7 to Windows 8.1 including the Windows RT versions.