This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

Microsoft severs ties with suspected patch-leaking partner

by Shaun Nichols

03 May 2012

View Comments

  • Tweet this

Microsoft has severed ties with a firm believed to have been leaking data on security vulnerabilities prior to the release of patches.

Microsoft said that Hangzhou DPTech Technologies had been removed from the Microsoft Active Protections Program (MAPP) for disclosing information on a zero-day flaw to outside researchers.

The decision stems from a March incident in which malware writers in China were able to develop a working exploit for a flaw in Windows Remote Desktop at roughly the same time as Microsoft released its patch for the vulnerability.

The MAPP system provides security developers with details on vulnerabilities ahead of Microsoft's monthly patch release, allowing vendors to patch their own products at the same time Microsoft discloses the flaws.

The early arrival of the Remote Desktop malware lead the company to suspect a vendor had handed the MAPP data over to third parties.

"Our goal with MAPP is to have a transparent, effective programme in place," wrote Microsoft senior program manager Maarten Can Horenbeack.

"As such, we routinely evaluate MAPP partners to ensure they are adhering to programme guidelines, taking action to correct any partner deviations from our programme charter."

The news comes as Microsoft prepares to issues the May edition of its Patch Tuesday security update.

The company said that the patch, planned for release on 8 May at roughly 1800 BST, would include three critical fixes and four important fixes.

The update will address remote code execution flaws in Microsoft Office, Windows and the .NET Framework as well as a pair of elevation of privilege vulnerabilities in Windows.

Do you agree

blog comments powered by Disqus

Poll

Business security poll

How concerned are you by the rising tide of cyber threats?

17%

54%

11%

9%

9%

Popular Threads

Powered by Disqus
Samsung Galaxy S4 V3

Samsung Galaxy S4 video review

A solid Android smartphone let down by less than stellar software

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

Delivery Project Manager - Energy, Risk Trading - London

Delivery Project Manager - Energy, Risk Trading - London...

Delivery Consultant - Trading Commodities, ETRM, Energy, Gas, P

Delivery Consultant - Trading Commodities, ETRM, Energy...

Senior Web Designer -Adobe Photoshop / HTML / CSS / InDesign

Senior Web Designer -Adobe Photoshop / HTML / CSS / InDesign...

C# Winforms / Desktop Developer - C# / WPF / SQL Server

C# Winforms / Desktop Developer - C# / WPF / SQL Server...

To send to more than one email address, simply separate each address with a comma.