Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


02:55 AM
Connect Directly

New Microsoft Program Helps Fix Third-Party Vulnerabilities

Microsoft to officially share with Windows third-party app vendors flaws it finds in their software

LAS VEGAS – Black Hat USA – Microsoft yesterday launched a program to help third-party Windows application vendors fix security flaws in their software. Under the new Microsoft Vulnerability Research (MSVR) program, Microsoft will share with those vendors vulnerabilities discovered by Microsoft researchers or outside researchers in these third-party products.

“We are extending security [research and resolution] to the Windows ecosystem,” says Mike Reavey, group manager for the Microsoft Security Response Center. “We wanted to formalize how we report to these vendors to share and leverage” Microsoft’s security resources.

The program reflects the shift in attack trends, with more exploits going after these third-party Windows apps, he says: Over 80 percent of exploits affecting XP systems are against third-party Windows apps, and over 90 percent affecting Vista systems are aimed at third-party Windows apps, according to Reavey.

Microsoft’s security experts find these vulnerabilities in third-party apps while working on their own research, or during the Security Development Lifecycle process. Reavey says a good example of how the MSVR process would work is the recent Apple Safari and Windows blended threat, which was initially discovered by an outside researcher who reported it to Microsoft: “We were able to work with Apple” to resolve it.

With MSVR, when Microsoft finds vulnerability in a third-party application, it would officially report it to the affected vendor and then help the vendor resolve it.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • Microsoft Corp. (Nasdaq: MSFT)

    Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    COVID-19: Latest Security News & Commentary
    Dark Reading Staff 9/25/2020
    9 Tips to Prepare for the Future of Cloud & Network Security
    Kelly Sheridan, Staff Editor, Dark Reading,  9/28/2020
    Attacker Dwell Time: Ransomware's Most Important Metric
    Ricardo Villadiego, Founder and CEO of Lumu,  9/30/2020
    Register for Dark Reading Newsletters
    White Papers
    Current Issue
    Special Report: Computing's New Normal
    This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
    Flash Poll
    How IT Security Organizations are Attacking the Cybersecurity Problem
    How IT Security Organizations are Attacking the Cybersecurity Problem
    The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    PUBLISHED: 2020-09-30
    An issue was discovered in MantisBT before 2.24.3. When editing an Issue in a Project where a Custom Field with a crafted Regular Expression property is used, improper escaping of the corresponding form input's pattern attribute allows HTML injection and, if CSP settings permit, execution of arbitra...
    PUBLISHED: 2020-09-30
    An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes are able to download the (supposedly private) attachments linked to these notes by accessing the corresponding file download URL directly.
    PUBLISHED: 2020-09-30
    An issue was discovered in MantisBT before 2.24.3. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when attempting to update said custom field via bug_actiongroup_page.php.
    PUBLISHED: 2020-09-30
    In Oniguruma 6.9.5_rev1, an attacker able to supply a regular expression for compilation may be able to overflow a buffer by one byte in concat_opt_exact_str in src/regcomp.c .
    PUBLISHED: 2020-09-30
    A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code by replacing the required DLLs with malicious DLLs when the software try to load vci11un6.DLL and cinpl.DLL.