Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Google clashes with Microsoft over Windows flaw disclosure (actively exploited zero-day vuln)
PC World ^ | Oct 31, 2016 | Michael Kan

Posted on 10/31/2016 6:41:58 PM PDT by dayglored

Google and Microsoft are butting heads over the disclosure of vulnerabilities. On Monday, Google revealed a critical flaw in Windows after it gave Microsoft a ten-day window to warn the public about it.

Google posted about the zero-day vulnerability on its security blog, saying Microsoft had yet to publish a fix or issue an advisory about the software flaw.

"This vulnerability is particularly serious because we know it is being actively exploited," Google said. It lets hackers exploit a bug in the Windows kernel, via a win32k.sys system call, to bypass the security sandbox.

The search giant originally told Microsoft about the problem 10 days ago, on Oct. 21. It waited to say anything about it publicly so Microsoft could fix the problem first. But Google has a strict policy of giving vendors only seven days to either publish a patch or issue a warning about a flaw.

"Seven days is an aggressive timeline and may be too short for some vendors to update their products," Google said in a blog post in 2013. "But it should be enough time to publish advice about possible mitigations."

Microsoft slammed Google's move. “We believe in coordinated vulnerability disclosure, and today’s disclosure by Google could put customers at potential risk," the company said in an email on Monday.

...

Google said that on Windows 10, its Chrome browser will prevent the problem from occurring. Using its own sandbox, the browser can block win32k.sys system calls.

(Excerpt) Read more at pcworld.com ...


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: chromebrowser; internet; internetsecurity; malware; microsoft; security; software; tech; windows; windowspinglist; zeroday
Navigation: use the links below to view more comments.
first previous 1-2021-26 last
To: dayglored
From http://venturebeat.com/2016/10/31/google-discloses-actively-exploited-windows-vulnerability-just-10-days-after-reporting-it-to-microsoft/:

Update at 12:45 p.m. Pacific: Microsoft issued a statement, though the company did not share when a patch could be expected.

“We believe in coordinated vulnerability disclosure, and today’s disclosure by Google puts customers at potential risk,” a Microsoft spokesperson told VentureBeat. “Windows is the only platform with a customer commitment to investigate reported security issues and proactively update impacted devices as soon as possible. We recommend customers use Windows 10 and the Microsoft Edge browser for the best protection.”

A source close to the company also shared that the exploit Google describes requires the Adobe Flash vulnerability. Since Flash has been patched, the Windows vulnerability is mitigated. That said, Microsoft still needs to plug the security hole as it could be leveraged in other types of attacks.

I added the bold.

21 posted on 11/01/2016 12:03:47 AM PDT by TChad
[ Post Reply | Private Reply | To 1 | View Replies]

To: MarchonDC09122009

You do understand that the government publishes vulnerability lists for ALL operating environments, right? Microsoft is NOT the only game in town. They’re the biggest, but they’re not the only one being tested. Apple and Android are regularly compromised and patched.


22 posted on 11/01/2016 6:06:44 AM PDT by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: rarestia

Of course.
The CERT list I sent contains bulletins pertaining to all software vulnerabilities.

The thread post was about Microsoft delaying addressing a serious vulnerability in a responsible manner, and hence discussion was directed accordingly.

All OS’s have vulnerabilities discovered on a regular basis.
Even Unix, ie: Redhat, AIX, Suse, etc.

Thx


23 posted on 11/01/2016 6:58:22 AM PDT by MarchonDC09122009 (When is our next march on DC? When have we had enough?)
[ Post Reply | Private Reply | To 22 | View Replies]

To: TChad
> A source close to the company also shared that the exploit Google describes requires the Adobe Flash vulnerability. Since Flash has been patched, the Windows vulnerability is mitigated.

Handy to know... thanks!

24 posted on 11/01/2016 1:25:11 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 21 | View Replies]

To: dayglored

bing


25 posted on 11/01/2016 1:29:31 PM PDT by jetson
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored; ShadowAce

Microsoft: Russian hackers are exploiting Windows flaw exposed by Google

The hacking group is one that has been linked to the Russian government, and is thought to have been behind a number of recent US hacks. Tensions are already running high between the US and Russia — particularly in light of American accusations that Russia has engaged in a hacking campaign designed to interfere with the election.

http://betanews.com/2016/11/02/russian-hackers-exploit-windows-security-flaw/


26 posted on 11/02/2016 4:38:12 AM PDT by AdmSmith (GCTGATATGTCTATGATTACTCAT)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-26 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson