On 31st October,2016 Google disclosed about major bug in Windows PCs publicly. As per Google, they detected some major vulnerabilities in Windows PCs and Adobe Flash. They mail both Microsoft and Adobe about those vulnerabilities via mail on 21st October, 2013.
Adobe had fixed their bug on 26th October, 2016. But Microsoft still not do anything for it.
As per policy of Google, after 7 days they discloses the vulnerability publicly to save users from the hackers. As Google said,"The hackers are actively exploiting user data from their PCs, and Microsoft is not doing anything to fix it.".
The bug affect the Window Kernel, a deepest and most privileged part of operating system and can be used to escape security sandbox, or tool designed to isolate malicious code. "It can be triggered via win32k.sys system call NtSetWindowLongPtr() for index GWLP_ID on window handle with GWL_STYLE set to WS_CHILD",Google said.
Normally Google waits 60 days before making such bugs publicly. But seeing the vulnerability on large section of users Google decided to disclose it earlier.
Source: Google Security Blog

No comments:
Post a Comment