Microsoft employee accidentally found XZ Utils backdoor

Microsoft published guidance and advice for the XZ Utils backdoor vulnerability, tracked at CVE-2024-3094. This vulnerability has a CVSS (Common Vulnerability Scoring System) score of 10 out of 10 and affects many Linux distributions, namely , Kali Linux, , Debian testing, Alpine, and it could have a huge global impact.

The vulnerability was accidentally discovered in time by a Microsoft Linux developer, Mr Andres Freund, who was curious because there was a 500ms delay on SSH (Secure Shell). So he discovered a backdoor built into the compressor XZ.

So far, VirtusTotal lists only four security vendors of the 63, including Microsoft, that can correctly identify the vulnerability.

According to the company's instructions, to verify if a system has a vulnerability , you can run the following command as root:
xz –version

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).