Microsoft has officially elevated Rust to the status of a first-tier programming language for its internal development, placing it on equal footing with C++, C#, and TypeScript. This move is part of a broader initiative to improve the security of its software, particularly by reducing vulnerabilities related to memory management. Historically, 70% of Microsoft's major security flaws stemmed from these types of issues, especially in C and C++. To address this, Microsoft is integrating Rust directly into its Visual C++ (MSVC) compilation environment, allowing both languages to share a common code generation system on Windows. This integration is particularly important for securing the Windows kernel, which is a core component of the operating system.
As part of this transformation, Microsoft is gradually rewriting key components of Windows, including the kernel, graphics drivers, and critical system services, using Rust. This effort is supported by significant financial investment in the Rust Foundation and its development tools to enhance the language’s ecosystem. The company is also focusing on modernizing drivers to improve system stability and reduce the occurrence of infamous “blue screen of death” (BSOD) errors caused by invalid memory access. Additionally, Microsoft is developing infrastructure that allows existing C++ code to coexist with new Rust code, ensuring backward compatibility without the need for an immediate rewrite of decades-old software.
Microsoft is also prioritizing Rust for new development projects, especially in the Azure cloud platform and Microsoft 365, where the use of C++ is being discouraged in favor of Rust. This aligns with the views of Mark Russinovich, a well-known Microsoft engineer, who has advocated for moving away from C++ in new projects. To further support this shift, Microsoft is funding research into using artificial intelligence to automatically convert legacy C/C++ code into Rust, aiming to make the transition more efficient.
Google has taken a similar approach, adopting Rust to reduce memory-related security vulnerabilities. The company has reported a 1,000-fold decrease in such issues since switching to Rust. However, Bjarne Stroustrup, the creator of C++, argues that the security of software depends largely on the skill and practices of the developers rather than the language itself. He proposes “Security Profiles” for C++ that impose constraints during compilation to enforce safer coding practices, without requiring entirely new language features. This approach allows for a more gradual and flexible evolution of C++ security, rather than a rigid shift to a new language like Rust. Despite these differing views, Rust is not expected to fully replace C and C++ in the near future due to challenges in adoption and performance considerations.
Microsoft Elevates Rust to First-Tier Language for Internal Development
AI-rewritten from original reportingHow it works
rustmicrosoftsecurityc-plus-pluswindowssoftware-development



