Singaporean regulator warns financial institutions about vulnerabilities in Microsoft Windows OS

Maria Nikolova

MAS has informed financial institutions using the affected Windows Operating Systems to take immediate action to install the relevant patches.

The Monetary Authority of Singapore (MAS) today issued a warning to financial institutions regarding vulnerabilities in the Microsoft Windows Operating System.

These vulnerabilities could allow malicious files or applications to bypass detection from security applications and gain control of the computer systems. MAS has informed financial institutions using the affected Windows Operating Systems to implement the relevant patches. Financial institutions should also take mitigating measures to prevent the vulnerabilities from being exploited.

The regulator explains that Microsoft released security updates for its Windows Operating Systems on January 15, 2020 to address 49 vulnerabilities. According to the Cyber Security Agency of Singapore (CSA), four of the vulnerabilities (CVE-2020-0601, CVE-2020-0609, CVE-2020-0610 and CVE-2020-0611) are highly critical and require immediate attention.

In particular, there is a Windows CryptoAPI spoofing vulnerability. It concerns the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a forged code-signing certificate to sign an executable file, making it appear that the file was from a trusted, legitimate source. The system or user would have no way of knowing the file was not legitimate, because the digital signature would appear to be from a trusted provider.

The security update addresses the vulnerability by ensuring that the Windows CryptoAPI validates the ECC certificates. After applying the patch, the user would be able to detect the usage of forged certificates via the Windows Event Logs.

The authorities also warn of Windows Remote Desktop Protocol (RDP) vulnerabilities. These include vulnerabilities in the Windows RDP Gateway Server, where they allow a pre-authenticated attacker to connect to a targeted system via RDP and sends crafted requests to trigger the execution of arbitrary code on the target system.

Another vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server.

MAS notes it will continue to work closely with financial institutions to monitor the cybersecurity developments and ensure that IT systems in the financial sector are safeguarded and remain resilient against cyber threats.

Read this next

Chainwire

BloFin Sponsors TOKEN2049 Dubai and Celebrates the SideEvent: WhalesNight AfterParty 2024

Platinum Spotlight: BloFin dazzles as the top sponsor of TOKEN2049 Dubai, elevating its status with the electrifying WhalesNight AfterParty 2024. Celebrate blockchain innovation and join the night where industry leaders and pioneers connect.

Institutional FX

Eddid helps HK crypto platforms with Bitcoin and Ether ETFs

The brokerage firm will help SFC-licensed virtual asset trading platforms with Bitcoin and Ether ETFs in Hong Kong.

Digital Assets

Cboe can save up to $15 million by closing crypto exchange

“Refocusing our digital asset business enables us to refine our strategy, leveraging our core strengths in derivatives, technology excellence and product innovation to help maximize opportunities for our business and deliver efficiencies for Cboe and our clients.”

Fintech

Sumsub adopts Europe’s new KYC standards for crypto

“Businesses are facing a rising regulatory tide where properly preparing for compliance is crucial. There is now a simple choice, whether to implement solutions that can deliver this, or instead risk significant financial and reputational damages.”

Chainwire

Bybit Web3 Launches Industry’s First Bitcoin Layer 2 Airdrop Campaign, Paving the Way for a New Bitcoin Era

Bybit, one of the world’s top three crypto exchanges by volume, is excited to announce that Bybit Web3 is launching the industry’s first Bitcoin Layer 2 Airdrop campaign through its Airdrop Arcade.

Retail FX

Vantage observes results of US$100,000 donation to UNHCR

Vantage’s US$100,000 donation has helped approximately 788 refugees, internally displaced persons (IDPs), and returnees in 2023 alone.

Executive Moves

Tradition hires Michel Everaert to integrate data science and AI

“I am excited about the potential this offers, and look forward to building relationships and working with teams across the global business.”

Retail FX

IBKR extends US Treasury bond trading to 22 hours per day

US Treasury bonds are highly sought after by investors seeking stability and security in their portfolios as these instruments are often considered one of the safest investment options. 

Market News

Navigating Yen Depreciation and Euro Resilience in Global Markets

Amidst the persistent depreciation of the Japanese yen against the US dollar, pressure mounts on Japanese policymakers to translate their verbal assurances into tangible actions.

<