• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechChanging Face of Security

Microsoft Just Closed a Security Gap That Affected Windows for Decades

By
David Meyer
David Meyer
Down Arrow Button Icon
By
David Meyer
David Meyer
Down Arrow Button Icon
June 17, 2016, 9:39 AM ET
Microsoft Corp. Launches Windows 10 In Japan
A visitor tries out Microsoft Corp.'s Windows 10 operating system on a tablet device during a launch event in Tokyo, Japan, on Wednesday, July 29, 2015. The release of Microsoft's new Windows 10 operating system -- an event that in years past sparked a surge of computer buying -- will do little to ease the four-year sales slump that's been dogging the PC industry. Photographer: Kiyoshi Ota/Bloomberg via Getty ImagesPhotograph by Kiyoshi Ota — Bloomberg via Getty Images

Microsoft (MSFT) sewed up an important security vulnerability this week, which has apparently affected Windows for the past two decades, making it possible to hijack the data flowing over the victim’s network and run malicious code on targeted computers.

The so-called BadTunnel vulnerability was discovered by Yang Yu, the director of Tencent’s (TCEHY) Xuanwu security lab. It allows attacks through a variety of Microsoft products such as Internet Explorer, the new Edge browser and Microsoft Office, as well third-party applications.

Yu, who earned a $50,000 “bug bounty” for reporting the discovery to Microsoft, told security news website Dark Reading that BadTunnel had “probably the widest impact in the history of Windows.”

Get Data Sheet, Fortune’s technology newsletter.

“It can be exploited silently with a near perfect success rate,” he said.

That said, there’s no evidence that the vulnerability has been exploited. Microsoft’s patch this Tuesday listed it as “important” rather than “critical.”

Rather than being an isolated flaw, as such, BadTunnel is a vulnerability that’s made possible by a combination of problems in how Windows handles networking and how Internet Explorer and Edge handle web pages.

In theory, it would someone to attack devices on an intranet from outside the network, despite the use of a protective firewall. Its exploitation would involve duping the victim into visiting a bad web page using Microsoft’s browsers, opening a dodgy Office document, or inserting a malicious USB drive.

For more on cybersecurity, watch our video.

Microsoft’s patch covers all the versions of Windows back from 10 to Vista, as well as versions of Windows Server 2008 and 2012. Windows XP is no longer supported, but it is vulnerable.

Yu will give more information on how individuals and organizations can protect themselves at the Black Hat USA 2016 security conference, which kicks off at the end of July.

About the Author
By David Meyer
LinkedIn icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Google Cloud revenue is now 18% of Alphabet’s business. Is this the beginning of the end of Google’s search identity?
Big TechGoogle
Google Cloud revenue is now 18% of Alphabet’s business. Is this the beginning of the end of Google’s search identity?
By Alexei OreskovicApril 29, 2026
4 hours ago
Man wearing a suit and tie and glasses
Big TechTech
Microsoft, Meta, and Google just announced billions more in AI spending. Only Google convinced investors it’s paying off
By Amanda GerutApril 29, 2026
5 hours ago
A man in a suit and tie
InvestingMeta
Meta just bumped its 2026 capex forecast up to as much as $145 billion for the AI boom—and investors flinched
By Amanda GerutApril 29, 2026
7 hours ago
How JPMorgan’s CIO is reshaping work at the bank with a $19.8 billion annual tech and AI budget
NewslettersCIO Intelligence
How JPMorgan’s CIO is reshaping work at the bank with a $19.8 billion annual tech and AI budget
By John KellApril 29, 2026
13 hours ago
hollywood
CommentaryMarketing
I spent 20 years learning to navigate an industry. Then I built a campaign for the man who’s dismantling it
By Matti YahavApril 29, 2026
17 hours ago
Current price of Ethereum for April 29, 2026
Personal FinanceEthereum
Current price of Ethereum for April 29, 2026
By Joseph HostetlerApril 29, 2026
17 hours ago

Most Popular

Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
Success
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
By Preston ForeApril 27, 2026
3 days ago
‘Take the money and run’: Johns Hopkins economist Steve Hanke on why the UAE quit OPEC
Energy
‘Take the money and run’: Johns Hopkins economist Steve Hanke on why the UAE quit OPEC
By Shawn TullyApril 29, 2026
23 hours ago
‘The cost of compute is far beyond the costs of the employees’: Nvidia executive says right now AI is more expensive than paying human workers
AI
‘The cost of compute is far beyond the costs of the employees’: Nvidia executive says right now AI is more expensive than paying human workers
By Sasha RogelbergApril 28, 2026
2 days ago
Jamie Dimon gets candid about national debt: ‘There will be a bond crisis, and then we’ll have to deal with it’
Economy
Jamie Dimon gets candid about national debt: ‘There will be a bond crisis, and then we’ll have to deal with it’
By Eleanor PringleApril 29, 2026
19 hours ago
‘They left me no choice’: Powell isn’t going anywhere—blocking Trump from another Fed appointee
Banking
‘They left me no choice’: Powell isn’t going anywhere—blocking Trump from another Fed appointee
By Eva RoytburgApril 29, 2026
11 hours ago
More than two-thirds of U.S. schools say they’re unable to afford the cost of student free lunch—and MAHA’s dietary guidelines may make it worse
Economy
More than two-thirds of U.S. schools say they’re unable to afford the cost of student free lunch—and MAHA’s dietary guidelines may make it worse
By Sasha RogelbergApril 29, 2026
21 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.