Singaporean regulator warns financial institutions about vulnerabilities in Microsoft Windows OS

Maria Nikolova

MAS has informed financial institutions using the affected Windows Operating Systems to take immediate action to install the relevant patches.

The Monetary Authority of Singapore (MAS) today issued a warning to financial institutions regarding vulnerabilities in the Microsoft Windows Operating System.

These vulnerabilities could allow malicious files or applications to bypass detection from security applications and gain control of the computer systems. MAS has informed financial institutions using the affected Windows Operating Systems to implement the relevant patches. Financial institutions should also take mitigating measures to prevent the vulnerabilities from being exploited.

The regulator explains that Microsoft released security updates for its Windows Operating Systems on January 15, 2020 to address 49 vulnerabilities. According to the Cyber Security Agency of Singapore (CSA), four of the vulnerabilities (CVE-2020-0601, CVE-2020-0609, CVE-2020-0610 and CVE-2020-0611) are highly critical and require immediate attention.

In particular, there is a Windows CryptoAPI spoofing vulnerability. It concerns the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a forged code-signing certificate to sign an executable file, making it appear that the file was from a trusted, legitimate source. The system or user would have no way of knowing the file was not legitimate, because the digital signature would appear to be from a trusted provider.

The security update addresses the vulnerability by ensuring that the Windows CryptoAPI validates the ECC certificates. After applying the patch, the user would be able to detect the usage of forged certificates via the Windows Event Logs.

The authorities also warn of Windows Remote Desktop Protocol (RDP) vulnerabilities. These include vulnerabilities in the Windows RDP Gateway Server, where they allow a pre-authenticated attacker to connect to a targeted system via RDP and sends crafted requests to trigger the execution of arbitrary code on the target system.

Another vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server.

MAS notes it will continue to work closely with financial institutions to monitor the cybersecurity developments and ensure that IT systems in the financial sector are safeguarded and remain resilient against cyber threats.

Read this next

Market News

Navigating Yen Depreciation and Euro Resilience in Global Markets

Amidst the persistent depreciation of the Japanese yen against the US dollar, pressure mounts on Japanese policymakers to translate their verbal assurances into tangible actions.

Digital Assets

El Salvador refutes rumors of Bitcoin wallet hack

Chivo Wallet, El Salvador’s official cryptocurrency wallet, has dismissed reports of a hack involving its software source code and the data of over 5 million users associated with its KYC (Know Your Customer) procedures.

blockdag

Best Crypto to Buy: BlockDAG Presale Hits $20.1M Following Moon-Shot Keynote Teaser as Dogecoin & Shiba Inu Prices Plummet

This landmark achievement sets it apart in the cryptocurrency landscape, where traditional favorites like Dogecoin and Shiba Inu are witnessing a price decline.

Digital Assets

MetaMask developer sues SEC over regulatory overreach

Ethereum ecosystem developer Consensys Software has filed a lawsuit against the U.S. Securities and Exchange Commission (SEC), challenging the agency’s regulatory actions concerning Ethereum and its related services.

Institutional FX

Tradeweb pulls in $408.7 million in Q1 revenue amid record trading volumes

Tradeweb Markets Inc. (NASDAQ: TW) has just announced its financial results for the first quarter of 2024, which showed a robust performance for the three months through March.

Institutional FX

BGC Group valued at $667 million following investment by major banks

BGC Group announced that its exchange platform, FMX Futures, is now valued at $667 million after receiving investments from a notable consortium of financial institutions.

blockdag

Transforming a Bankrupt Investor into a Cryptocurrency Giant; Can BlockDAG Replicate Ethereum’s Meteoric Rise With 30,000x Predictions?

The realm of cryptocurrency investing presents a thrilling blend of challenges and opportunities. The legendary gains by early Ethereum investors serve as a powerful lure for those seeking the next major breakthrough.

Digital Assets

SEC delays decision on spot bitcoin options ETFs

The U.S. Securities and Exchange Commission (SEC) has postponed its decision on whether to authorize options trading on spot bitcoin ETFs, extending the review period by an additional 45 days. The new deadline for the SEC’s decision is now set for May 29, 2024.

Market News, Tech and Fundamental, Technical Analysis

Solana Technical Analysis Report 25 April, 2024

Solana cryptocurrency can be expected to fall further toward the next support level 130.00, target price for the completion of the active impulse wave (i).

<