• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

The U.S. campaigned to host the World Cup. Now soccer fans will trade their countries' train system for the U.S.'s 'D' rated infrastructure

2

Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year

3

Nvidia CEO Jensen Huang admits he criticizes everything his 42,000-plus employees show him: ‘You can’t go a day without some criticism’

1

The U.S. campaigned to host the World Cup. Now soccer fans will trade their countries' train system for the U.S.'s 'D' rated infrastructure

2

Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year

3

Nvidia CEO Jensen Huang admits he criticizes everything his 42,000-plus employees show him: ‘You can’t go a day without some criticism’
TechMicrosoft

Researchers Discovered a Big Security Flaw In This Important Microsoft Product

By
Jonathan Vanian
Jonathan Vanian
Down Arrow Button Icon
By
Jonathan Vanian
Jonathan Vanian
Down Arrow Button Icon
August 7, 2019, 4:51 PM ET

Researchers have found a big security hole in some popular Microsoft software that they speculate could have impacted the company’s Azure cloud computing service.

Check Point researchers revealed their findings on Wednesday about a security vulnerability that affects Microsoft’s Hyper-V software, used by companies to create so-called virtual machines. With virtual machines and related virtualization technology, a single computer can function as several, letting companies more efficiently operate their data center infrastructure.

Hyper-V is an important virtualization product for Microsoft that is used in Azure and Windows 10, according to Check Point.

The security flaw was related to a previous bug Check Point discovered that affected Microsoft’s Remote Desktop Protocol (RDP) software, widely-used by corporate IT administrators to remotely access employee computers for troubleshooting.   

Check Point’s head of cyber research, Yaniv Balmas, told Fortune that a hacker could exploit the flaw to take control of a computer. All the hacker must do is to trick victims — though a phishing attack, for example—into unwittingly connecting their computers to the hacker’s malware-infected machine via the RDP software.

Although Check Point notified Microsoft about the original RDP bug, Microsoft decided the flaw wasn’t serious enough to create a software patch to fix the problem, Balmas said. After Check Point publicly released its findings about the original RDP bug, other security researchers contacted the company to ask if Check Point researchers were aware if the flaw affected the Hyper-V software as well, Balmas said.

Some of the same technology that powers RDP is also used for the “enhanced session” feature within Hyper-V that lets people remotely connect their computers to virtual machines.

Realizing that the original vulnerability impacted a commonly used Microsoft virtualization product, Balmas said Check Point contacted Microsoft again, which changed its tune about fixing the problem.

“When we told this to Microsoft, they said, ‘Hold on a second, you’re right, this is big,’” Balmas said. “Then they started taking care of this very quickly, very responsibly, and did a very good job.”

A Microsoft spokesperson confirmed that the company fixed the security bug in July. It’s unclear whether any hackers used the flaw to access anyone’s computer.

“Customers who apply the update, or have automatic updates enabled, will be protected,” the spokesperson said in a statement. “We continue to encourage customers to turn on automatic updates to help ensure they are protected.”

Balmas speculated that the vulnerability affected Microsoft’s Azure cloud computing service in some way, because Hyper-V helps Azure create and manage virtual machines for users. He said he asked Microsoft if the vulnerability Check Point discussed was “applicable to Azure” to verify his assumption, but the company never directly responded.

Although Check Point found the Hyper-V flaw, it couldn’t verify whether it impacted Azure because that would have required engaging in hacking others.

“This is not something we can do legally or ethically,” Balmas said.

Microsoft did not respond to Fortune’s inquiry into whether the security flaw affected Azure in some way.

“We really can’t get a straight answer for them, and I can understand why,” Balmas said. It’s likely Microsoft does not want to draw any negative attention to possible security holes in Azure.

Check Point announced its findings at the annual Black Hat cybersecurity conference in Las Vegas.

Security in cloud computing has recently become a hot topic, with Capital One, an Amazon Web Services customer, admitting that a hacker and former-AWS employee illegally accessed the personal information of over 100 million of its credit card users.   

Coincidentally, earlier this week, Microsoft debuted Azure Security Lab, which lets outside researchers test security flaws in Azure without breaking the entire service. Researchers who spot and exploit Azure security bugs could potentially earn up to $300,000, the company said.

Balmas said that the new Azure Security Lab will help the Check Point researchers continue their testing of the flaw it found.

“So this makes it easier for us,” Balmas said. “It came after we complained.”

More must-read stories from Fortune:

—What you need to know about 8chan, the controversial site tied to the El Paso shooting

—Verizon’s unlimited plans are getting cheaper. Here’s what you should know

—What CEOs, bankers, and tech execs think about a coming recession

—How an alleged Amazon theft ring got the goods

—Boeing adds a second flight control computer to the 737 Max

Catch up with Data Sheet, Fortune‘s daily digest on the business of tech.

About the Author
By Jonathan Vanian
LinkedIn iconTwitter icon

Jonathan Vanian is a former Fortune reporter. He covered business technology, cybersecurity, artificial intelligence, data privacy, and other topics.

See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

The unlikely origin of a $2.5 billion hospitality unicorn: a bored teenager working the night shift at his family business
Workplace CultureHospitality
The unlikely origin of a $2.5 billion hospitality unicorn: a bored teenager working the night shift at his family business
By Catherina GioinoMay 27, 2026
17 minutes ago
AI is changing the hospitality industry, and it’s changing how you stay in hotels
Future of WorkHospitality
AI is changing the hospitality industry, and it’s changing how you stay in hotels
By Catherina GioinoMay 27, 2026
40 minutes ago
zuck
LawSupreme Court
Supreme Court lets Vermont’s Meta lawsuit proceed, opening door to 50-state legal wave
By Lindsay Whitehurst and The Associated PressMay 27, 2026
2 hours ago
new
Big TechObituary
Donald Newhouse saw the internet coming in 2004. His newspapers still weren’t ready
By Scott Mayerowitz and The Associated PressMay 27, 2026
2 hours ago
bezo
Innovationspace
NASA just awarded its first moon base contracts—and Jeff Bezos was on the list
By Marcia Dunn and The Associated PressMay 27, 2026
2 hours ago
leo
InnovationAutos
Ferrari presents Pope with its first ever electric car, stock plunges 8%
By Alexa St. John and The Associated PressMay 27, 2026
2 hours ago

Most Popular

The U.S. campaigned to host the World Cup. Now soccer fans will trade their countries' train system for the U.S.'s 'D' rated infrastructure
Travel & Leisure
The U.S. campaigned to host the World Cup. Now soccer fans will trade their countries' train system for the U.S.'s 'D' rated infrastructure
By Catherina GioinoMay 25, 2026
2 days ago
Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year
Success
Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year
By Preston ForeMay 21, 2026
6 days ago
Nvidia CEO Jensen Huang admits he criticizes everything his 42,000-plus employees show him: ‘You can’t go a day without some criticism’
Success
Nvidia CEO Jensen Huang admits he criticizes everything his 42,000-plus employees show him: ‘You can’t go a day without some criticism’
By Preston ForeMay 26, 2026
1 day ago
The Supreme Court handed Trump a Golden Chariot on tariffs — now he just has to take it
Commentary
The Supreme Court handed Trump a Golden Chariot on tariffs — now he just has to take it
By Jeffrey Sonnenfeld and Steven TianMay 26, 2026
1 day ago
Current price of silver as of Tuesday, May 26, 2026
Personal Finance
Current price of silver as of Tuesday, May 26, 2026
By Joseph HostetlerMay 26, 2026
1 day ago
Uber burned through its entire 2026 AI budget in four months. Now its COO is questioning whether it's worth it
AI
Uber burned through its entire 2026 AI budget in four months. Now its COO is questioning whether it's worth it
By Jake AngeloMay 26, 2026
22 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.