Microsoft Services unaffected by OpenSSL "Heartbleed" vulnerability

JMH

Emeritus, Contributor
Joined
Apr 2, 2012
Posts
7,197
On April 8, 2014, security researchers announced a flaw in the OpenSSL encryption software library used by many websites to protect customers’ data. The vulnerability, known as “Heartbleed,” could potentially allow a cyberattacker to access a website’s customer data along with traffic encryption keys.

After a thorough investigation, Microsoft determined that Microsoft Account, Microsoft Azure, Office 365, Yammer and Skype, along with most Microsoft Services, are not impacted by the OpenSSL “Heartbleed” vulnerability. Windows’ implementation of SSL/TLS is also not impacted. A few Services continue to be reviewed and updated with further protections.

Microsoft always encourages its customers to be vigilant with the security of their online accounts, change their account passwords periodically and to use complex passwords. More information on how to create strong passwords is available here: Microsoft Security & Safety Center: Create strong passwords.
Microsoft Services unaffected by OpenSSL "Heartbleed" vulnerability - Microsoft Security Blog - Site Home - TechNet Blogs
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top