Google discloses actively exploited Windows vulnerability just days after reporting it

Discussion in 'other security issues & news' started by ronjor, Oct 31, 2016.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,145
    Location:
    Texas
    Emil Protalinski October 31, 2016 11:10 AM

     
  2. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    What happened to 90 days they usually give vendor to patch their software?
     
  3. TheWindBringeth

    TheWindBringeth Registered Member

    Joined:
    Feb 29, 2012
    Posts:
    2,171
    From the link above:
     
  4. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Thnx for links @TheWindBringeth. Although I wouldn't expect MS to patch and test win32k.sys in one week. Luckily Flash was updated so exploit doesn't work any more. We can only hope that MS will release patch before new ways to exploit vulnerability are found.
     
  5. TheWindBringeth

    TheWindBringeth Registered Member

    Joined:
    Feb 29, 2012
    Posts:
    2,171
    I take you clicked through and saw this, but it might be good to surface:
     
  6. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Yes I saw this. Although in this case they could give MS more time, since Flash was patched and advicing users to update Flash would be enough to mitigate ITW exploits ( at least I read it that way).
    I also don't know how users could protect themselfs against attack that targets kernel component - what steps can users take to protect against this specific vulnerability?
     
  7. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,145
    Location:
    Texas
    Our commitment to our customer’s security
     
  8. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    Microsoft attacks Google's Windows hack alert
     
  9. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,145
    Location:
    Texas
    They should. Irresponsible of Google.
     
  10. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    Microsoft says Russia-linked hackers exploiting Windows flaw
    Link: http://www.reuters.com/article/us-microsoft-cyber-russia-idUSKBN12W4ZK

     
  11. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    98,062
    Location:
    U.S.A.
  12. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,145
    Location:
    Texas
    Microsoft Patches Windows Zero-Day Exploited by Russian Hackers
     
  13. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    https://mspoweruser.com/googles-project-zero-security-researchers-drop-another-bomb-microsoft/
     
  14. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.