Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Microsoft confirms FREAK vulnerability affects Windows as well

Microsoft confirms FREAK vulnerability affects Windows as well

Kareem Anderson Kareem Anderson
October 22, 2019
2 min read

Microsoft confirms FREAK vulnerability affects Windows as well

For some, their high horse ride has come to an end. Windows users who were standing on their soap boxes and pointing fingers at Android, Mac OS and iOS users who were subjects of an SSL/TLS vulnerability, will now join them to some degree.

Microsoft confirmed today, the FREAK Attack vulnerability that exists in Secure Channel (Schannel), affects all versions of Windows.  The Schannel is a security package that implements the SSL/TLS authentication protocols. The authentication process can now be used as an exploit that allows would-be attackers the ability to downgrade an encrypted SSL/TLS session while forcing client systems to use a weaker and export-grade RSA cipher in the process.

Essentially this is a man-in-the-middle (MITM) exploit that allows attackers the ability to intercept and decrypt  encrypted traffic. Bad stuff.

This FREAK Attack is garnering a lot of attention as it is  reported to have affected more than a third of HTTPS servers with browser-trusted certificates. Most of the top used browsers have been or are affected including, Internet Explorer, Chrome on OSX, Android, Safari, iOS, stock AOSP Android browser, BlackBerry browser, Opera on OSX,  and Linux.

Microsoft confirms FREAK vulnerability affects Windows as well

Google has already issued a patch for Chrome on OSX and Apple will be following suit with a patch for Safari sometime next week.

While Microsoft says that they have found no evidence that this exploit has been in use for Windows users, they will be making an effort (possibly applying an off-scheduled update) to address this attack.

“Upon completion of this investigation, Microsoft will take the appropriate action to help protect customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.”

There are precautions Windows users can take while they wait for Microsoft to patch this vulnerability. Microsoft is advising that Windows users disable RSA key exchange using Group Policy Object Editor, which has been an available option in Windows since Vista. This stop-gap disables the attacker’s ability to launch the FREAK attack as it is reliant on server support of export-grade cipher suites.

Further reading: Attack, Chrome, Microsoft, OSX, Safari, Vulnerability, Windows

Share this article:
Tags:
Attack Chrome Microsoft OSX Safari Vulnerability Windows
Previous Article Windows 10 build 9834 has leaked onto the internet with Remind Me app included Next Article Spartan browser to support extensions in Windows 10, similar to Google Chrome

Related Articles

Red Magic 11 runs PC games like GTA 5 and Cyberpunk 2077 on Android at 60 FPS

April 4, 2026

New Ryzen 9 9950X3D2 loses performance on air cooling

April 4, 2026

Legion Go 2 now costs $1,999 at Best Buy, pricing no longer makes sense

April 4, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Red Magic 11 runs PC games like GTA 5 and Cyberpunk 2077 on Android at 60 FPS
  • New Ryzen 9 9950X3D2 loses performance on air cooling
  • Legion Go 2 now costs $1,999 at Best Buy, pricing no longer makes sense
  • ELSA Launches GigaIO Gryf Portable AI System with Modular Design
  • NASA Artemis II astronauts face Outlook issues in space as mission hits unexpected software glitch

Recent Comments

  1. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  2. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Red Magic 11 runs PC games like GTA 5 and Cyberpunk 2077 on Android at 60 FPS
  • New Ryzen 9 9950X3D2 loses performance on air cooling
  • Legion Go 2 now costs $1,999 at Best Buy, pricing no longer makes sense
  • ELSA Launches GigaIO Gryf Portable AI System with Modular Design
  • NASA Artemis II astronauts face Outlook issues in space as mission hits unexpected software glitch

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy