Windows 7 Update appears to be compromised?

Anonymous
2015-09-30T11:04:55+00:00

These details of "Important" update, which I received this morning - 4:30 AM MT.  Copied to Notepad:

(appears to be a language pack?  4.3 MB)

______________________________________________________

gYxseNjwafVPfgsoHnzLblmmAxZUiOnGcchqEAEwjyxwjUIfpXfJQcdLapTmFaqHGCFsdvpLarmPJLOZYMEILGNIPwNOgEazuBVJcyVjBRL

Download size: 4.3 MB

You may need to restart your computer for this update to take effect.

Update type: Important

qQMphgyOoFUxFLfNprOUQpHS

More information: 

https://hckSLpGtvi.PguhWDz.fuVOl.gov

https://jNt.JFnFA.Jigf.xnzMQAFnZ.edu

Help and Support: 

https://IIKaR.ktBDARxd.plepVV.PGetGeG.lfIYQIHCN.mil

________________________________________________________________________

Did NOT install.  After my MSE definitions updated, I repeated Windows Update.  The above 'important' update did not reappear???

Did MS servers get compromised?

Thank you

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

46 answers

Sort by: Newest
  1. Anonymous
    2015-09-30T18:10:43+00:00

    Actually the way patches are digitally signed, and it has to match up with a Microsoft cert authority while one never says anything is impossible, one can't inject something into the update without first compromising the entire OS's cert checking process.  And in this case, an attacker would be REALLY stupid to go through all that trouble to compromise the cert checking process and then blow it on the actual attack sequence.

    This is true. Unfortunately, that system has indeed already been compromised at least once. http://www.wired.com/2012/06/flame-microsoft-certificate/ 

    People can reasonably be concerned and mistrust their computers until they get a clear answer.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2015-09-30T18:05:31+00:00

    It's not the first time someone [or probably these days some computer] in charge of the approve button approved something it wasn't supposed to approve.  Hang tight, I'm not giving up on getting official word.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2015-09-30T18:01:21+00:00

    This is good to know, it sounds like for some reason, Microsoft just let an update through that our computers shouldn't need. It is a language update (some sort of Cyrillic) and in my case, it did not install on any of the computers. I hid the update, and once I rechecked it did not show back up. 

    JG

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2015-09-30T17:55:57+00:00

    I think Microsoft needs to check this one out... Too many people are downloading this, and Microsoft has NOT said that it is a legitimate update. I have had it download on three computers (one at a very large institution running Windows 7 Enterprise... The fonts appear to be Cyrillic fonts, but I am not absolutely certain.

    JG

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2015-09-30T17:55:19+00:00

    The link isn't a FQDN:

    bleh://⁠rr1winwusfs04/⁠c/⁠msdownload/⁠update/⁠software/⁠defu/⁠2015/⁠09/⁠testexe_896e3a62-⁠8954-⁠447b-⁠5a562bd65cc6_d5e430cb05ee8a627ee6d811da8d7c4ccea57f4b.exe

    This looks more like an admin made a boo boo and exposed an internal testing server...notice the path and "testexe"..I doubt this is malicious.

    Was this answer helpful?

    0 comments No comments