Remember Stuxnet? Discovered in mid-2010, this malware is probably one of the most striking examples of cyberweapons developed with government backing. In August of that same year, Microsoft released a patch intended to fix the vulnerability that Stuxnet exploited, but there's a small detail: the patch never worked, and users have been exposed to similar attacks for nearly five years.

The Patch That Was Supposed to Protect Windows From Stuxnet Has Been Broken for Five Years
Stuxnet

A patch that never worked

The second Tuesday of March has come and gone, and as expected, the Redmond giant delivered another batch of patches to harden security across its various Windows versions. Still, nobody can deny that Microsoft's hotfix work has been more than disappointing in recent months. Corrupted fonts, patches that remove other patches, bugs that take a year of work … the list goes on. Now we add a vulnerability that has been with us for nearly five years, but the most serious part is that it had already been fixed in August 2010. The MS10-046 bulletin, presented as "critical" at the time, describes a vulnerability in the shell32.dll file when processing elements with the .LNK extension to render icons when a USB drive is connected. This is the same vulnerability that let Stuxnet blow up a fifth of the Iranian centrifuges and infect protected systems via an "airgap".

The Patch That Was Supposed to Protect Windows From Stuxnet Has Been Broken for Five Years
Stuxnet gets a second round five years later

The follow-up that finishes the job

Users received the hotfix, half a decade passed, and yesterday a new bulletin was published, MS15-020. What this new patch does is finish the job that the previous fix never completed. According to researchers at the Zero Day Initiative of Hewlett-Packard, the original patch failed, and users have been unprotected since then. HP also added that the vulnerability, under official designation CVE-2010-2568, was the most exploited in 2014, accounting for about a third of attacks. This data presents two possibilities: either many connected systems still did not receive the hotfix from bulletin MS10-046 in the first place, or attackers applied some reverse engineering and found new holes.

In short… install the new update. It's likely that on an average system, the "patch that fixes the patch" will be accompanied by ten or eleven other hotfixes, among them two that fix the so-called FREAK attack (a "man in the middle" that forces the use of weaker encryption modes), and the effects of the Superfish malware. The big question is what surprise we'll run into next month...

Hewlett-Packard