Bonum Certa Men Certa

The Latest Bug Door in Windows 'Patched', But the Patch Breaks Systems



"Our products just aren't engineered for security."

--Brian Valentine, Microsoft executive



AND THEN WE TOLD CHINA THEY CAN SEE WINDOWS CODE WHILE INVITING THE NSA TO THE FINAL BUILD PROCESS



Summary: Errors in Windows that facilitate remote access and privilege escalation (affecting every version of Windows) continue to surface and those who fix these errors risk bricking their systems/services

Having just made (generated rather, using an online tool) the above meme to make an important point (pardon the "Windows" typo), we wish to bring together some recent news about Microsoft Windows, probably the least secure operating system in the world (by design). The NSA is involved in finalising Windows development and knowing what many people finally know about the NSA, it oughtn't be shocking that Windows uses weakened/flawed encryption, enables remote access, etc.



Earlier this month there was a lot of press coverage about a massive flaw and an "emergency" patch for Windows. The NSA, for a fact (based on Snowden's leaks), already knew about this. It knew about before it was patched, as Microsoft tells the NSA about every flaw before patches are applied and flaws become common knowledge.

Stephen Withers, a booster of Microsoft from Australia, said that a "very old but only just fixed Windows vulnerability is the key to a new in-the-wild attack.

"Security vendor ESET says it has detected a real-life exploit for a vulnerability that's been part of Windows for nearly two decades."

So it's not just exploitable by the NSA anymore.

Over at IDG, this flaw was said to have a botched 'solution'. As the author put it: "Last Tuesday's MS14-066 causes some servers to inexplicably hang, AWS or IIS to break, and Microsoft Access to roll over and play dead"

So patch or don't patch, you are in a serious problem either way. Welcome to the "professional" and "enterprise-ready" world of Microsoft.

As Microsoft boosters put it, "Microsoft has announced that they will be pushing an out-of-band security patch today. The patch, which affects nearly all of the company's major platforms, is rated 'critical' and it is recommended that you install the patch immediately."

To brick one's system?

Here is what British press wrote about it:

MICROSOFT HAS ISSUED an emergency patch for the Kerberos Bug that could allow an attacker to perform privilege escalation in several versions of Windows.

In what will be the firm's third emergency patch in the past three months, the fix arrives just a week after the monthly Patch Tuesday release.


In other curious news from the same source, British taxpayers' money has just been wasted cleaning up the mess of Microsoft Windows with its baked-in back doors. Windows is being hijacked en masse, but the corporate media refers to it as "PC", not Windows. This is a crucial omission. The insecurity of Windows is not always accidental. It was designed to be easy to access (only by the "Good Guys", of course!). "THE UK NATIONAL CRIME AGENCY (NCA) has arrested five people," said the British press, "as part of a crackdown on hackers who hijack computers using Remote Access Trojans (RATs)." It's a shame that they don't point out that it's a Windows-only problem. It doesn't even take much in terms of skill to hijack Windows, as many hackers and crackers can attest to. To quote this report: "The NCA said on Friday that it has arrested two 33-year-old men and a 30-year-old woman from Leeds, along with a 20 year-old man from Chatham in Kent and a 40-year-old from Darlington in Yorkshire."

This 20 year-old cracker is about as old as the latest bug door from Microsoft. With 19-year-old flaws in Windows ("critical" too) it oughtn't be hard to hijack Windows-running PCs by the millions and even by the billions. As this article put it, the flaw is very severe and "Microsoft's out-of-band update yesterday fixes a profoundly serious bug: Any user logged into the domain can elevate their own privilege to any other, up to and including Domain Administrator."

Robert Pogson wrote that Microsoft "told the world they were naked and now system administrators are scurrying around to make sure every system running InActive Directory has a patch."

As usual, no logos and brand names for this bug, not even the huge media hype that we saw when GNU Bash and OpenSSL had a bug in them. Perhaps the media learned to accept that Windows is Swiss cheese, or more likely it is unconsciously complicit in Microsoft's PR.

Comments

Recent Techrights' Posts

The Reputation Issue Is Not Our Fault
Trying to squash words (and people) merely diverts more attention to them
 
Whistleblowing is About Understanding Boundaries and Risks
The bottom line is, people typically find out the truth at the end
EPO People Power - Part XXV - While EPO Managers Snort Cocaine the Staff Compiles 'Insurance Files' to Expose EPO Corruption
In this increasingly authoritarian world we need more whistleblowers
"The European Patent Reform" That Represents a Gross Violation of Laws, Constitutions, and Conventions (in Order to Make the Rich Even Richer, Mostly Outside Europe)
How far and how long will EPO corruption go?
GNU/Linux Distribution "Ultimate Edition" Fixes Its Web Site (Apparently Compromised Months Ago)
they dealt with the issue before media shame and a catastrophe of trust
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, January 04, 2026
IRC logs for Sunday, January 04, 2026
Gemini Links 04/01/2026: 64-bit Addressing and 39th Chaos Communication Congress
Links for the day
Windows Was Always the Punchline
What did we count to calculate taxes?
GNU/Linux Surges to About 4% in Peru This Year
one of the poorest counties in America
This Year Our Adoption of IRC Turns 18
We have used IRC for this site since 2008
The Doors Are Closing, Windows Closing Too
Microsoft wants more vendor lock-in, but at risk that this desire will simply alienate and drive away many users
The FSF's Program Manager, Dr. Miriam Sabrina Bastian, Left in October to Lead Climate School
We are not sure why Miriam Bastian decided to leave the Free Software Foundation (FSF)
Outline of Slop, LLMs, IBM, and Things to Come
This coming week and weekend will be very productive irrespective of how much "news" gets published by other sites
Links 04/01/2026: War Without Borders, "Large Hadron Collider Being Shut Down"
Links for the day
Links 04/01/2026: US Imperialism in Greenland and Venezuela, "Climate Protesters Face Greater Risk of Crackdown Amid Rising Authoritarianism"
Links for the day
2026 Should be the Year We All Stop Saying "AI" and Call Things What They Really Are
Don't give anyone the satisfaction of this misguided belief there's any intelligence there
Ponzi Schemes Are Useful (to Corrupt CEOs)
Pathetic, corruptible so-called 'media' is bagging bribes to perpetuate the lies about "AI" (slop)
GNU/Linux at All-Time High in Algeria
In 2026 it hit a new all-time high
Online Mobbing (and Worse) Disguised as 'Free Speech'
People who say they believe in "free speech" have been trying hard to silence RMS and squash the FSF
A 'Cancer That Attaches Itself' to Bulgaria?
"Cancer" is what Microsoft called GNU/Linux
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, January 03, 2026
IRC logs for Saturday, January 03, 2026
Body-Shaming Using Fakes
a lot of the people who casually claim "defamation" are themselves defaming loads of people every day
GNU/Linux "Market Share" in Switzerland More Than Doubled Last Year, Based on statCounter
GNU/Linux continues its considerable growth
EPO People Power - Part XXIV - Today or Tomorrow You Should Write to National Representatives (Delegates) at the EPO in Your Country
Keep up the pressure!
Red Hat and IBM Layoffs, Staff Kept Quiet About it, WARN Act Skirted/WARN Notices Avoided
What a terrible company to be in
XBox Layoffs Imminent, More Appalling Sales Figures Published
Expect many layoffs in the gaming division
Slop Still Rare
So far a good start for 2026
Gemini Links 03/01/2026: Climbing, Waking Up, and Social Control Media Woes
Links for the day
Links 03/01/2026: Growing Censorship, Another US Invasion, and Will Smith 'Cancelled'
Links for the day
Links 03/01/2026: Twitter Turns From Disinformation Powerhouse to Production and Dissemination of Child Pr0n, "New China Cybersecurity Law Becomes A Reality In 2026"
Links for the day
Gemini Links 03/01/2026: Formatting Text for Gopher and Text-only Websites
Links for the day
Unverified Claim: Mass Layoffs at Microsoft to Start Around Week 3 (or 4) of This Month
Let's wait and see if the claim above is from an insider who has inside knowledge
Firefox Fell Below 1% in Asia
less than 1 in 100 Web users is detected/assumed to be using Firefox
Links 03/01/2026: Ryanair Fines and Facebook Misleads Regulators
Links for the day
New Record High for GNU/Linux in Benelux in 2026
If the above trends stand (throughout the year), then we can begin talking more seriously about a post-GAFAM Europe
In the Search Engine Market, Microsoft is Falling Behind Russia's Yandex
The so-called 'AI industry' is a boy that cries wolf
A Year of Relaxation, But Also of Hardcore Whistleblowing
Expect industrial action some time soon
The More Influential Richard Stallman (RMS) Becomes, the More Aggressive Attacks on Him (and the FSF) Will Get
We've meanwhile noticed disinformation being spread in social control media
GNU/Linux Reaches All-Time High of 5% in Indonesia (Not Counting Chromebooks and Android)
There are also related events in Indonesia and SUSE in particular seems to have been popularised there
EPO People Power - Part XXIII - António Campinos Knows He's Extremely Vulnerable at This Time
Campinos should never have been put in charge
Gemini Links 03/01/2026: New Organisation System (Notebooks) and "2026 Already Off to an Amazing Start"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, January 02, 2026
IRC logs for Friday, January 02, 2026