H&R Block Business 2025 installs a backdoor on your machine which allows anyone to snoop and manipulate your encrypted internet traffic.
To secure your computer, you must manually remove this certificate from the Local Machine certificate stores.
certlm.msc and press Enter. (Click "Yes" if prompted by User Account Control).TLS is the backbone of internet security. It is what protects your internet traffic from unscrupulous eyes. When you visit a website that begins with "HTTPS" and you see a pad-lock icon on your browser, the traffic is protected by TLS. When TLS is used correctly, the only people who can see your internet traffic is you and the website you are communicating with. However, when an untrusted "root certificate" is installed, anyone who has the private key to that certificate can silently re-direct that traffic and see what you are doing as well as manipulate the content you see. This includes but is not limited to your emails, online banking, social media, and private messages. See this page for more details.
H&R Block Business 2025 installs a root certificate named "WK ATX ServerHost 2024" into your computer's trusted root certificate store. This root certificate has a known private key that is included with the software package meaning anyone who can see your encrypted internet traffic is now able to decrypt it. Worse of all, when you normally uninstall the software, the root certificate does not get deleted so unless you follow the uninstall steps on this page, your computer will still be vulnerable. Currently, only H&R Block Business 2025 is known to be vulnerable and other editions and versions have not been tested.
If you got a warning or error message from your web browser when visiting this page, then you are not vulnerable. Even if you are vulnerable, this does not automatically mean your data has been compromised. You should follow the instructions above and remove this back door as soon as possible. In order for an attacker to use this backdoor, they would need to be able to see your (normally encrypted) internet traffic. Common entities who may be able to use this backdoor include: anyone on a shared or public Wi-Fi that you are connected to, anyone in a shared building (apartment, business, etc), your landlord or boss or parent or guardian (if they installed monitoring software on the network), your internet service provider, your VPN provider, government entities, and other nation-states.
Unfortunately, there is no general way to tell. If you are a business who uses an endpoint security product, contact them about possible indicators of attacks based on network traffic. If your computer is vulnerable AND you suspect a website you visit (excluding this one) may be attacked, click on the pad-lock icon on your browser and check if the name "WK ATX ServerHost 2024" appears in the list of certificates. If it appears, then you are being attacked and you can assume all your internet traffic is being actively monitored or manipulated by a third party. If it does not appear, then either you are safe or the attack may not be active at that moment.
After review with the program team, we're closing this report as out of scope. The reported issue involves an executable application that falls outside our defined program scope, and similar findings have been identified through internal security assessments.