Windows 7 Update appears to be compromised?

Anonymous
2015-09-30T11:04:55+00:00

These details of "Important" update, which I received this morning - 4:30 AM MT.  Copied to Notepad:

(appears to be a language pack?  4.3 MB)

______________________________________________________

gYxseNjwafVPfgsoHnzLblmmAxZUiOnGcchqEAEwjyxwjUIfpXfJQcdLapTmFaqHGCFsdvpLarmPJLOZYMEILGNIPwNOgEazuBVJcyVjBRL

Download size: 4.3 MB

You may need to restart your computer for this update to take effect.

Update type: Important

qQMphgyOoFUxFLfNprOUQpHS

More information: 

https://hckSLpGtvi.PguhWDz.fuVOl.gov

https://jNt.JFnFA.Jigf.xnzMQAFnZ.edu

Help and Support: 

https://IIKaR.ktBDARxd.plepVV.PGetGeG.lfIYQIHCN.mil

________________________________________________________________________

Did NOT install.  After my MSE definitions updated, I repeated Windows Update.  The above 'important' update did not reappear???

Did MS servers get compromised?

Thank you

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

46 answers

Sort by: Newest
  1. Anonymous
    2015-09-30T17:37:38+00:00

    Actually the way patches are digitally signed, and it has to match up with a Microsoft cert authority while one never says anything is impossible, one can't inject something into the update without first compromising the entire OS's cert checking process.  And in this case, an attacker would be REALLY stupid to go through all that trouble to compromise the cert checking process and then blow it on the actual attack sequence.

    "Simply injecting content into the update description" isn't simple at all.  It feels more like a Microsoft patch oopsie than anything nefarious.  Bottom line the update mechanism isn't easily compromised, typically requires physical access or some sort of physical injection of the cert attack (as I recall Flame malware injected itself with compromised USB devices).  It's one of the reasons that Microsoft can do peer to peer updating in Windows 10 and can assure that the bits coming to us from anywhere are still official Microsoft bits.

    My point was if something is listed in the update history as failed you can't "hide" that one item, the update database doesn't work that way.

    My gut tells me someone oopsie'd on Microsoft's side and I'm doing my best to confirm.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2015-09-30T17:23:36+00:00

    He's looking at the WSUS Console (Windows Server Update Services). It's a part of the Windows Server OS's

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2015-09-30T17:23:14+00:00

    Its from a server running WSUS.  Unless you're managing a large network with centralized patch deployment, you won't have anything like that.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2015-09-30T17:16:18+00:00

    What software is the screenshot you posted from, please?

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2015-09-30T17:10:56+00:00

    If the update didn't install, it didn't install.  The fact that it's listed in your update history doesn't mean that it's impacted your system.  

    If the update mechanism was compromised and attackers were able to inject content then you have no assurances of that. Depending on what vulnerabilities exist in the update mechanism, then simply injecting content into the update description could be enough to cause remote code execution.

    That said, this looks more like a font / character encoding issue and isn't necessarily a sign of intrusion.

    Was this answer helpful?

    0 comments No comments