{"id":296,"date":"2015-03-11T09:03:41","date_gmt":"2015-03-11T09:03:41","guid":{"rendered":"http:\/\/borncity.com\/win\/?p=296"},"modified":"2022-10-02T01:24:53","modified_gmt":"2022-10-01T23:24:53","slug":"microsoft-fixes-freak-vulerability-but-not-on-windows10tp","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2015\/03\/11\/microsoft-fixes-freak-vulerability-but-not-on-windows10tp\/","title":{"rendered":"Microsoft fixes FREAK vulnerability, but not on Windows 10 TP"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"http:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/win102.jpg\" width=\"58\" align=\"left\" height=\"58\">Yesterday Microsoft has released several updates to fix security issues in Windows, IE, Office, Exchange Server. One patch fixed the FREAK vulnerability \u2013 but not on Windows 10.<\/p>\n<p><!--more--><\/p>\n<p>I've blogged about patch day issues a couple of hours ago in my German patch day triptych:<\/p>\n<p><a href=\"http:\/\/www.borncity.com\/blog\/2015\/03\/10\/microsoft-patchday-sicherheits-updates-mrz-2015\/\">Microsoft-Patchday: Sicherheits-Updates M\u00e4rz 2015 \u2013 Teil 1<\/a><br \/><a href=\"http:\/\/www.borncity.com\/blog\/2015\/03\/10\/microsoft-patchday-weitere-updates-mrz-2015-teil-2\/\">Microsoft-Patchday: weitere Updates M\u00e4rz 2015 \u2013 Teil 2<\/a><br \/><a href=\"http:\/\/www.borncity.com\/blog\/2015\/03\/11\/mrz-2015-patchday-infos-stuxnet-freak-superfish-mehr\/\">M\u00e4rz 2015 Patchday-Infos: Stuxnet, FREAK, SuperFish &amp; mehr<\/a> \u2013 Teil 3 <\/p>\n<p>and summed some things up. One was the FREAK vulnerability. I've written about FREAK in my recent blog post <a href=\"https:\/\/borncity.com\/win\/2015\/03\/10\/microsofts-freak-workaround-causes-update-error-8024001f\/\">Microsoft's FREAK workaround causes update error 8024001F<\/a>. Also ZDNet.com has an article <a href=\"http:\/\/www.zdnet.com\/article\/how-to-protect-yourself-against-freak\/\" target=\"_blank\" rel=\"noopener noreferrer\">about FREAK here<\/a>. <\/p>\n<h3>A fix for FREAK vulnerability<\/h3>\n<p>Microsoft has released KB3046049<em> (<\/em><em>MS15-031<\/em><em>) Vulnerability in Schannel Could Allow Security Feature Bypass <\/em>to fix this issue. I've tested it this night, using <a href=\"https:\/\/web.archive.org\/web\/20160317233640\/https:\/\/freakattack.com\/clienttest.html\">this web site<\/a>, an I got the following message in IE 11 under Windows 7.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/web.archive.org\/web\/20160926143006\/http:\/\/a48.imgup.net\/FREAK01f7b3.jpg\"> <\/p>\n<p>Hey, seems cool, and my MVP collegue Ed Bott wrotes <a href=\"http:\/\/www.zdnet.com\/article\/march-2015-patch-tuesday\/\" target=\"_blank\" rel=\"noopener noreferrer\">here at ZDNet.com<\/a> that the update is avaiable for all Windows versions. But that's not true! <\/p>\n<h3>Attention: No fix for FREAK in Windows 10 TP Build 9926<\/h3>\n<p>After running the test above, I decided to take a sleep (it was just Midnight here in Germany). This moring a German blog reader asks, what's going wrong with this patch, because his IE 11 still shows a vulnerability in Windows 10 TP (Build 9926). Here is, what I got on my test machine (IE 11 under Windows 10 TP, Build 9926). <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/web.archive.org\/web\/20160926143007\/http:\/\/s10.imgup.net\/FREAK-02-W025d.jpg\" width=\"634\" height=\"501\"> <\/p>\n<p>Ups, that thing is still vulnerable for FREAK Attacks. The explanation is simple: Microsoft doesn't provide a patch for FREAK (if I don't overlooked something). This night there has been one 4 patches issued to Windows 10 TP.  <\/p>\n<p><img decoding=\"async\" src=\"https:\/\/web.archive.org\/web\/20160926143007\/http:\/\/m36.imgup.net\/Update-03-7b99.jpg\"> <\/p>\n<ul>\n<li><a href=\"http:\/\/t.co\/VtEcgyB9Ba\">support.microsoft.com\/kb\/3039066<\/a><\/li>\n<li><a href=\"http:\/\/support.microsoft.com\/kb\/3044132\">http:\/\/support.microsoft.com\/kb\/3044132<\/a><\/li>\n<li><a href=\"http:\/\/support.microsoft.com\/kb\/3032359 \">http:\/\/support.microsoft.com\/kb\/3032359 <\/a><\/li>\n<li><a href=\"http:\/\/support.microsoft.com\/kb\/890830\">http:\/\/support.microsoft.com\/kb\/890830<\/a><\/li>\n<\/ul>\n<p>See also Gabe Aul's <a href=\"https:\/\/twitter.com\/GabeAul\/status\/575378276538970112\" target=\"_blank\" rel=\"noopener noreferrer\">tweet here<\/a>. As far as I see, there is no patch for <em>KB3046049 (MS15-031).<\/em> I've added <a href=\"https:\/\/twitter.com\/etguenni\/status\/575584830878056448\" target=\"_blank\" rel=\"noopener noreferrer\">a comment to Gabe Aul's tweet<\/a> to ask for further details, but have no answer so far.<\/p>\n<p>&nbsp;<a href=\"https:\/\/borncity.com\/win\/wp-content\/uploads\/2015\/03\/Aul-03-2015.jpg\"><img loading=\"lazy\" decoding=\"async\" title=\"Aul-03-2015\" style=\"border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px\" border=\"0\" alt=\"Aul-03-2015\" src=\"https:\/\/borncity.com\/win\/wp-content\/uploads\/2015\/03\/Aul-03-2015_thumb.jpg\" width=\"398\" height=\"188\"><\/a> <\/p>\n<p>To summarize it: FREAK vulnerability hasn't been fixed in Windows 10 TP Build 9926 till yet, because <a title=\"http:\/\/support.microsoft.com\/kb\/3046049\" href=\"http:\/\/support.microsoft.com\/kb\/3046049\" target=\"_blank\" rel=\"noopener noreferrer\">KB3046049<\/a> isn't available for Windows 10 (only for lower Windows versions). <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Yesterday Microsoft has released several updates to fix security issues in Windows, IE, Office, Exchange Server. One patch fixed the FREAK vulnerability \u2013 but not on Windows 10.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[122,65,3,76],"class_list":["post-296","post","type-post","status-publish","format-standard","hentry","category-windows","tag-freak-vulnerability","tag-microsoft","tag-patchday","tag-windows-10"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/296","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=296"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/296\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=296"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=296"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=296"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}