Bonum Certa Men Certa

Microsoft Finally Admits Numbers of Vulnerabilities It Reports Are Fake

Microsoft lies



Summary: Mike Reavey, the director of the Microsoft Security Response Center, admits that Microsoft is silently patching vulnerabilities without ever reporting the problem

IT'S official. Microsoft is a liar. Again. Now there is even admission from Microsoft, confirming an issue which we first raised some weeks ago. Whenever Microsoft says it patches x number of flaws with y number of patches/bulletins, Microsoft ought to be assumed to be lying. Microsoft's silent patching is a subject we have been covering for years and it helps explain why one in two Windows PCs is believed to be a zombie PC, despite Microsoft's claims that all of its flaws are being addressed. All those fake comparisons against platforms like Red Hat Enterprise Linux (where Microsoft stacks up and aggregates numbers of flaws) can be thrown into the wastebasket. If convincing proof is needed, here it is. Microsoft first tried to spin it (for weeks) and now it gives up and tells the truth.



Microsoft Official Admits to Quiet Security Patching



Microsoft doesn't report all security vulnerabilities that it fixes in its software. Bug comparisons between vendors therefore paint an incorrect picture.

"We don't document every issue found," Mike Reavey, director of the Microsoft Security Response Center (MSRC), said at a meeting with reporters at the company's corporate headquarters in Redmond, Washington.

Microsoft will issue a Common Vulnerabilities and Exposures (CVE) number to a vulnerability for flaws that share the same severity, have an attack vector and a workaround. If several flaws share all the same properties, they will not be reported separately, Reavey said.

The nondisclosure of fixes was brought to light early this month by a company called Core Security Technologies. After studying the Microsoft patches MS10-024 and MS10-028, it noticed three silent fixes. Security bulletin MS10-028 addressed a flaw that would expose a user of Microsoft Visio to a buffer overflow attack, which would allow an attacker to take over control of the system.


Finally. Thanks for the honesty. So how much damage has been caused by Microsoft's lies so far. Microsoft has been denying this for years, but not exactly denying, either. It was spinning and avoiding the actual question. It's the art of lying without practically lying, just evading. Adobe is at least honest about its proprietary software being insecure garbage. As far as we are aware, Adobe hasn't a long history of systematic lying, unlike Microsoft.

"Microsoft smacks patch-blocking rootkit second time," says another new report from Gregg Keizer.

For the second month in a row, Microsoft has tried to eradicate a mutating rootkit that has blocked some Windows users from installing security updates.


Here is another one (also here):

Jerry Bryant, a group manager with the Microsoft Security Response Center (MSRC), said his team is looking into Raskin's claims, but hinted that Microsoft wouldn't be patching IE anytime soon. "I wouldn't classify this as a 'vulnerability' though," Bryant said in an e-mail answer to questions.


The followup says:

Will browser makers patch this? Unlikely. Microsoft's Jerry Bryant, a general manager at the company's security response center, said the issue isn't a security vulnerability per se, and that Internet Explorer (IE) falls for the scam because that's the way browsers work.

"Working with [Raskin's] proof-of-concept, as written, is expected," he said in an e-mail Tuesday when asked whether Microsoft had a fix in mind for IE.


Let's remember how much damage was caused this year because Microsoft had refused to patch known Internet Explorer flaws for five months [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12]. Where is the liability [1, 2, 3, 4, 5]? Watch what it happening in Denver right now.

Denver officials have asked the FBI, Denver police and Microsoft Corp. to help them identify the person or people who have hacked into the city's website twice in the past week.


If Microsoft gets involved, then it almost must be a Windows server.

Comments

Recent Techrights' Posts

In Europe, More People Turn to Russia for Answers, Not Microsoft
The future of computing doesn't look pretty
SLAPP Censorship - Part 48 Out of 200: Brett Wilson LLP and 5RB Copy-Pasting Bogus Claims for Violent Americans (Microsoft) Who Tell Women to Kill Themselves
Microsoft's Graveley telling his partner to kill herself is probably a crime
 
Massive, Cross-Site Strike at the EPO Today
There's coordination across sites for maximal pressure
Dr. Andy Farnell Says "AI" is "Only a Marketing Term" for Things That Exist for "Entertainment Purposes Only"
distortion or misuse of the term (now buzzword/s) "AI"
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, April 16, 2026
IRC logs for Thursday, April 16, 2026
Strikes at the EPO Carry on, Staff Union of the European Patent Office (SUEPO) Increases Pressure Ahead of Technical and Operational Support Committee (TOSC) Meeting Next Week
the local section The Hague (or SUEPO TH) wants to rally many staff members
Gemini Links 16/04/2026: LLM Nuisance, Identity Systems (Surveillance), and Why Windows is Failing
Links for the day
'Going Offline' is Not Primitivism
Computers are good at automation, but people are not robots
The Register MS Has Published Article With "AI" 18 Times in it, "Cloud" 9 Times. It Got Paid to Do This.
What happened to journalism?
The EFF Is Hardly Doing Anything Anymore
Our series about the EFF has been brewing for over 2 years already
Microsoft Uses Slop to Bribe (at No Cost) Nations That Otherwise Would Move to GNU/Linux and IBM is Forcing Red Hat Staff to Use Slop
Life it too short to waste "consuming" slop
Links 16/04/2026: Roblox Launching ‘Roblox Kids’ Accounts and "Deepfake Nudes Crisis in Schools"
Links for the day
Red Hat Staff: IBM Red Hat Laid Off About 400 Engineers, the Media Did Not Cover This
The media is not doing its job or doing a really shoddy job
Gemini Links 16/04/2026: Nocturnal Pulse, Unpersoned Outlaws, and Monaspace Lagrange Fontpacks
Links for the day
Richard Stallman Lecture in GDC Auditorium in Austin, Texas
corporate power could not 'cancel' the man
It's Not About the Head, It's About the Masters (and Funding)
Regardless of who the OSI claims to be its leader, its masters are Microsoft, just follow the money
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, April 15, 2026
IRC logs for Wednesday, April 15, 2026
Links 15/04/2026: Geelong Corio Refinery Fire, Journalist Sentenced for "Insulting the President"
Links for the day
Gemini Links 15/04/2026: Organiding .bashrc with Imports, Oddμ as SSG
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, April 14, 2026
IRC logs for Tuesday, April 14, 2026