|
|
|
|
|
by cesarb
2344 days ago
|
|
I haven't seen it mentioned anywhere yet, but I have to wonder... Does this vulnerability allow MITM of Windows Update itself? I would expect all connections to the Windows Update servers to be protected with TLS, and as a second layer the updates themselves to be signed, but if this vulnerability allows bypassing both signatures, this could be really bad. |
|
Later
Dmitri Alperovitch at Crowdstrike says this doesn't impact Windows Update.