Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Windows 7 Zero-Day Unpatched Vulnerability Is Being Exploited in the Wild (my title)
Google Security Blog ^ | Mar 7, 2019 | Clement Lecigne

Posted on 03/08/2019 8:34:11 PM PST by dayglored

Article title: "Disclosing vulnerabilities to protect users across platforms"

... The second vulnerability was in Microsoft Windows. It is a local privilege escalation in the Windows win32k.sys kernel driver that can be used as a security sandbox escape...

We strongly believe this vulnerability may only be exploitable on Windows 7 due to recent exploit mitigations added in newer versions of Windows. To date, we have only observed active exploitation against Windows 7 32-bit systems.

Pursuant to Google’s vulnerability disclosure policy, when we discovered the vulnerability we reported it to Microsoft. Today, also in compliance with our policy, we are publicly disclosing its existence, because it is a serious vulnerability in Windows that we know was being actively exploited in targeted attacks. The unpatched Windows vulnerability can still be used to elevate privileges or combined with another browser vulnerability to evade security sandboxes. Microsoft have told us they are working on a fix.

As mitigation advice for this vulnerability users should consider upgrading to Windows 10 if they are still running an older version of Windows, and to apply Windows patches from Microsoft when they become available. We will update this post when they are available.


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: faketitle; windows; windows7; windowspinglist; zeroday
The Google blog post title wasn't very descriptive of the problem so I made one that was.

Microsoft has not yet patched this flaw.

Those of us who prefer Windows 7 to Windows 10 need to be aware that these things are out there, and that come January 2020 when Microsoft stops releasing security updates for Windows 7, we're going to have our tushes in the breeze.

1 posted on 03/08/2019 8:34:12 PM PST by dayglored
[ Post Reply | Private Reply | View Replies]

To: Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; AppyPappy; arnoldc1; ATOMIC_PUNK; bajabaja; ...
Windows 7 Zero-Day Vulnerability ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to ShadowAce for the ping!

2 posted on 03/08/2019 8:35:08 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
A great article at Art Technica on this topic:
A “serious” Windows 0-day is being actively exploited in the wild
Unfortunately, Ars Technica cannot be used as a thread source on FreeRepublic.
3 posted on 03/08/2019 8:36:59 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
" and that come January 2020 when Microsoft stops releasing security updates for Windows 7, we're going to have our tushes in the breeze to migrate over to Linux and rid ourselves of this madness.
4 posted on 03/08/2019 8:37:03 PM PST by BipolarBob (Dad, Send lawyers, guns and money.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Does anyone know if Window 98 is vulnerable to this attack?

Wondering if I should upgrade my operating system.


5 posted on 03/08/2019 8:54:27 PM PST by gunsequalfreedom
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
As mitigation advice for this vulnerability users should consider upgrading to Windows 10 if they are still running an older version of Windows

No thanks.

6 posted on 03/08/2019 9:07:51 PM PST by wastedyears (The left would kill every single one of us and our families if they knew they could get away with it)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Required title :

Disclosing vulnerabilities to protect users across platforms


7 posted on 03/08/2019 9:21:28 PM PST by TexasGator (Z1z)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
Well, since I blocked all MS updates, no problems on W 7.

Wish I could do the same for my wife's W 10 laptop that freezes during updates, requires re-connect to the wi-fi after some damn thing or another.

Farqing MS with the eternal diddling.

8 posted on 03/08/2019 10:00:47 PM PST by doorgunner69
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

I can assure you that this vulnerability is hogwash.

Now, may I interest you in great opportunity? I am Nigerian prince attempting to escape my country from civil unrest. Help me remove my fortune of 50 million American dollars from country. I will need your bank account. I will give you 10 percent cut. PM me for details.


9 posted on 03/08/2019 10:45:30 PM PST by Greetings_Puny_Humans (I mostly come out at night... mostly.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

I love my Windows 7!!!!!!!!


10 posted on 03/08/2019 10:55:12 PM PST by Maudeen (JESUS . . .The United States of America's ONLY Hope)
[ Post Reply | Private Reply | To 1 | View Replies]

To: gunsequalfreedom

Well, they had to wrest 98 out of my hands to upgrade to Win 7.


11 posted on 03/08/2019 11:04:19 PM PST by angry elephant (My MAGA cap is from a rally in Washingon state in May 2016)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Maudeen

I still use W7 but it keeps telling me to upgrade my browser. It’s all Greek to me. I just hope I don’t lose all my pix and files come 2020!


12 posted on 03/09/2019 2:23:55 AM PST by FES0844
[ Post Reply | Private Reply | To 10 | View Replies]

To: gunsequalfreedom; dayglored
Does anyone know if Window 98 is vulnerable to this attack? Wondering if I should upgrade my operating system:non:  .

Definitely you should upgrade to the latest Windows operating system, Windows Millennium, especially for the improved desktop.

System requirements for running Windows ME

Minimum Recommended x86 CPU : Pentium, 150 MHz Memory: 32 MB Hard drive: 320 MB

If you have any problems with this advanced system, contact dayglored

13 posted on 03/09/2019 5:15:14 AM PST by daniel1212 (Trust the risen Lord Jesus to save you as a damned and destitute sinner + be baptized + follow Him)
[ Post Reply | Private Reply | To 5 | View Replies]

To: FES0844
I just hope I don’t lose all my pix and files come 2020!

Just pick up a USB flash drive (Wal-Mart, Office Max, any computer shop) and save your pix etc on to it. You'll have an easy way to transfer them to your next computer.

14 posted on 03/09/2019 5:25:53 AM PST by deoetdoctrinae (Donate monthly and end FReepathons.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: deoetdoctrinae

Thank you. Will ask my daughter to get for me.


15 posted on 03/09/2019 5:33:00 AM PST by FES0844
[ Post Reply | Private Reply | To 14 | View Replies]

To: dayglored
...Microsoft has not yet patched this flaw. ...

In which case neither will they admit it exists. Which is one intrinsic difference between how M$ and the *NIX community operate.

16 posted on 03/09/2019 8:11:38 AM PST by Paal Gulli
[ Post Reply | Private Reply | To 1 | View Replies]

To: Maudeen
I love my Windows 7!!!!!!!!

Win 7 BUMP!!

Amen.

17 posted on 03/09/2019 8:19:22 AM PST by upchuck (Home schooled kids are educated, not indoctrinated.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: daniel1212; gunsequalfreedom
> If you have any problems with this advanced system, contact dayglored

You may well laugh at WinME, it more than earned everyone's derision.

But Win98 SE (Second Edition) was actually a very good single-user, personal (non-business), non-internet OS. It had no security to speak of, but then, those were arguably more innocent days. :-)

I have a VM (virtual machine) of Win98SE. On modern hardware it screams, and it runs my few remaining ancient 90's applications, frankly just as well as Win7 does.

But rather than upgrade to WinME, I would either stay with Win98SE or migrate to WinXP. Granted, Win2000 defined my ideal desktop GUI, and forever afterward, my first steps when installing a fresh copy of XP or 7 is to set the desktop GUI back to Win2000 mode. The fact that Win10 blocks me from doing so (even with the addition of ClassicShell) is one of the reasons I refuse to run Win10 as my default Windows environment. I have a Win10 VM around for software compatibility testing, and to run a few Win10-only applications, but no more than that.

So I'd say, stick with Win98SE if that's what you like. Why? Because it's NOT vulnerable to this attack!! LOL, seriously; AFAIK this vulnerability like most other ones these days, only affects the NT-based editions.

OTOH, stay the heck off the internet with Win98 or any of the DOS-based Windows. They're totally vulnerable to a million other attacks.

18 posted on 03/09/2019 10:46:05 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 13 | View Replies]

To: daniel1212

#13 I still use the blue background color of windows in that photo. I have Windows 7.


19 posted on 03/09/2019 10:44:27 PM PST by minnesota_bound
[ Post Reply | Private Reply | To 13 | View Replies]

To: dayglored
I have a VM (virtual machine) of Win98SE. On modern hardware it screams, and it runs my few remaining ancient 90's applications, frankly just as well as Win7 does.

Sorry for not seeing this reply till now, but in conjunction with what you said, I noticed long ago when switching to XP on much better hardware that on basic tasks, like opening folders or something like Notepad, that W/9x was noticeably faster. Things would just like instantly jump into view, whereas with XP and later there was a bit of a lag. Although on this AMD 4350 (4.2ghz) basic things come up very quickly unless the CPU is heavily laden (and under 9x that meant keeping an eye on system resources). Thank God for what we have under grace in Christ.

20 posted on 03/19/2019 11:20:07 AM PDT by daniel1212 (Trust the risen Lord Jesus to save you as a damned and destitute sinner + be baptized + follow Him)
[ Post Reply | Private Reply | To 18 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson