Singaporean regulator warns financial institutions about vulnerabilities in Microsoft Windows OS

Maria Nikolova

MAS has informed financial institutions using the affected Windows Operating Systems to take immediate action to install the relevant patches.

The Monetary Authority of Singapore (MAS) today issued a warning to financial institutions regarding vulnerabilities in the Microsoft Windows Operating System.

These vulnerabilities could allow malicious files or applications to bypass detection from security applications and gain control of the computer systems. MAS has informed financial institutions using the affected Windows Operating Systems to implement the relevant patches. Financial institutions should also take mitigating measures to prevent the vulnerabilities from being exploited.

The regulator explains that Microsoft released security updates for its Windows Operating Systems on January 15, 2020 to address 49 vulnerabilities. According to the Cyber Security Agency of Singapore (CSA), four of the vulnerabilities (CVE-2020-0601, CVE-2020-0609, CVE-2020-0610 and CVE-2020-0611) are highly critical and require immediate attention.

In particular, there is a Windows CryptoAPI spoofing vulnerability. It concerns the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a forged code-signing certificate to sign an executable file, making it appear that the file was from a trusted, legitimate source. The system or user would have no way of knowing the file was not legitimate, because the digital signature would appear to be from a trusted provider.

The security update addresses the vulnerability by ensuring that the Windows CryptoAPI validates the ECC certificates. After applying the patch, the user would be able to detect the usage of forged certificates via the Windows Event Logs.

The authorities also warn of Windows Remote Desktop Protocol (RDP) vulnerabilities. These include vulnerabilities in the Windows RDP Gateway Server, where they allow a pre-authenticated attacker to connect to a targeted system via RDP and sends crafted requests to trigger the execution of arbitrary code on the target system.

Another vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server.

MAS notes it will continue to work closely with financial institutions to monitor the cybersecurity developments and ensure that IT systems in the financial sector are safeguarded and remain resilient against cyber threats.

Read this next

blockdag

Analysts Go Bullish On BlockDAG After Its Surge to $0.005 And Unique Developer Platform That Goes Beyond Ethereum & BONK

Discover how BlockDAG’s unique low-code and no-code platforms offer more adaptability than Ethereum’s bull run and BONK’s fluctuating prices.

Tech and Fundamental, Technical Analysis

WTI crude oil Technical Analysis Report 23 April, 2024

WTI crude oil can be expected to rise further toward the next major resistance level 86.00, which has been reversing the price from October.

Digital Assets

Binance Debuts Spot Copy Trading Feature in Its Expanding Automated Trading Portfolio

Explore Binance’s latest innovation in trading technology with the rollout of Spot Copy Trading, now available within their comprehensive automated trading toolkit.

Financewire

Changelly launches Probably Serious Quiz introducing 0% fee swaps of USDt on TON and Toncoin

Changelly, a global crypto exchange, lists USDt on TON, a newly launched stablecoin created in the wake of a strategic collaboration between Tether and The Open Network.

Digital Assets

Crypto.com’s South Korea launch hits a snag over AML probe

Crypto.com has postponed a planned launch in South Korea following a report by the local news outlet Segye Ilbo, which stated that the exchange platform was undergoing an “urgent on-site inspection” due to concerns over money laundering.

Market News

Germany’s DAX 40 Index: Defying Economic Gravity

Amidst a backdrop of pervasive pessimism regarding Germany’s economic outlook, the DAX 40 Index (Germany 40 Mini at FXOpen) has emerged as a beacon of resilience and strength in the European financial landscape.

blockdag

DotBig Investments: Transforming the Landscape of Investment Opportunities

DotBig, a prominent player in the investment landscape, offers a diverse range of opportunities for both private and corporate investors.

Fintech

Uncleared OTC derivatives post-trade processing has a new player

A recent platform trial conducted by Fragmos Chain in partnership with a consortium of six investment banks across Europe, Asia, and North America, has been deemed a success.

Interviews

Colibrix wants to take the LATAM payments market by storm

FinanceFeeds is excited to announce an exclusive interview with Aleksander Bobrov, CEO of Colibrix, delving deep into the payment firm’s recent advancements and strategic positioning in the Latin American (LATAM) market.

<