Skip to main content

Tech: Microsoft: Google's Policy Endangers Windows Users

Google on Monday posted to the Internet a previously unpublicized flaw that could pose a security threat to users of the Microsoft Windows operating system.

Google notified both Microsoft and Adobe of zero day vulnerabilities in their software on Oct. 21, wrote Neel Mehta and Billy Leonard, members of Google's Threat Analysis Group, in an online post.

Google has a policy of making critical vulnerabilities public seven days after it informs a software maker about them. Adobe was able to fix its vulnerability within seven days; Microsoft was not.

"This [Windows] vulnerability is particularly serious because we know it is being actively exploited," wrote Mehta and Leonard.

However, Google's Chrome browser prevents exploitation of the vulnerability when running in Windows 10, they added.

Flaw Not Critical

Microsoft challenged Google's analysis of the Windows flaw in a statement provided to TechNewsWorld by spokesperson Charlotte Heesacker.

"We disagree with Google's characterization of a local elevation of privilege as 'critical' and 'particularly serious,' since the attack scenario they describe is fully mitigated by the deployment of the Adobe Flash update released last week," Microsoft said.

After cracking a system, hackers typically try to elevate their privileges in it to obtain access to increasingly sensitive data.
"Additionally, our analysis indicates that this specific attack was never effective against the Windows 10 Anniversary Update due to security enhancements previously implemented," Microsoft noted.

The Windows vulnerability Google's team discovered is a local privilege escalation in the Windows kernel that can be used as a security sandbox escape triggered by a win32k.sys call, according to Mehta and Leonard.

The sandbox in Google's Chrome browser blocks win32k.sys calls using the Win32k lockdown mitigation on Windows 10, which prevents exploitation of the sandbox escape vulnerability, they explained in their post.

Short Deadline

Although Google contrasted Adobe's quick action in patching its zero day vulnerability with Microsoft's inaction, the comparison may be less than fair.

"The time to patch code in Adobe Reader or Flash versus something that integrates into an operating system is considerably different," said Brian Martin, director of vulnerability intelligence at Risk Based Security.

What takes time is not so much changing the code as testing it after it's changed, he explained.

"If Microsoft patches code in one version of Windows, it will likely affect several other versions," Martin told TechNewsWorld.

"Then they have platform issues -- 32-bit and 64-bit -- and then the different versions -- home, professional, server, whatever," he pointed out.

"The amount of time it takes to patch it is one thing," he said. "The amount of time to go through the full QA cycle is another. Seven days is generally considered unrealistic for an operating system."

To Disclose or Not

The short deadline was necessary because it saw the vulnerability being exploited by hackers, Google's team maintained. That logic, though can be a two-edged sword.
"To me, this doesn't ultimately help achieve everyone's goal, which should be keeping consumers and their data safe," said Udi Yavo, CTO of enSilo.

"By disclosing a vulnerability early, without allowing time for a patch, Google opened up the small pool of people who found the vulnerability and knew how to exploit it, to all," he told TechNewsWorld.

However, keeping the vulnerability under wraps at all is questionable, suggested Jim McGregor, principal analyst at Tirias Research.

"Considering how closely the hacker community communicates, seven days may have been too much time," he told TechNewsWorld.

"Google was being a friendly corporate citizen by letting Microsoft know about the vulnerability, but in my mind it would have been more appropriate to make it public knowledge once you see it in the wild," McGregor said.
"A vulnerability can spread though the hacker community in milliseconds," he remarked. "By not making the vulnerability public, the only people who don't know about it are the people who should know about it." 

Readers Choice

Lead Your Team Into a Post-Pandemic World

During the Covid-19 crisis, I’ve spoken with many CEOs who have shared that a key priority for them, naturally, has been the safety and well-being of their employees. And there are many examples of inspiring actions taken by CEOs and companies in support of their employees. But as we’ve come to recognize that this crisis will last more than a few short weeks, companies are now defining their approach for the long haul. I’ve seen two crucial ideas take hold with corporate leaders. One: Given the magnitude of the shock and the challenges that this crisis represents, companies must consider the full breadth of their employees’ needs as people. Safety is essential, of course, but it’s also important to address higher-level needs such as the want for truth, stability, authentic connections, self-esteem, growth, and meaning in the context of the crisis. Two: Many CEOs have begun thinking about this crisis in three phases. They may assign different names or specific lengths to t

List of Cloud Certifications

Cloud certifications and Cloud computing certifications are very young, but their value grows so fast. Managers and IT specialist want to extend their knowledge about neutral cloud topics, but also vendor-specific implementations. Few of them, like Arcitura Education with the CloudSchool program, CompTIA or EXIN created vendor neutral certifications. The biggest vendors like VMware, HP, EMC, Microsoft and IBM have in their portfolio also Cloud certifications, that help you prove your skills about products and technologies. On the horizon we can see other vendors like Huawei or Cisco with new certifications. Strong cloud skills are for sure a good trend for companies (on the management level) and also engineers or IT architects. List of Cloud Certifications 52 Certifications 13 Vendors Amazon AWS Amazon AWS has in the offer three certifications and works on new ones. At this moment you can pass exams on associate level for architects, developers and SysO

Twenty Smart Business Buzzwords

Some words may grate on your nerves, but business leaders are still using "disrupt," "synergy" and "ideate." You should too. Spend any amount of time in a corporate environment and you'll likely notice there are some words that seem to come up on a daily basis. Certain verbiage becomes part of the  corporate culture  and soon, you may feel as if you need to use it to fit in. While they can change from one day to the next, most corporate buzzwords have a positive meaning. They're used to boost morale and motivate everyone involved in the conversation. Here are 20 of the top business buzzwords that you should make an effort to work into your vocabulary. 1. Impact Impact is a powerful word that has become a favorite of business professionals.  Grammarians argue  that the word is being used improperly, urging you to use "affect" instead, but businesses love it. 2. Corporate Synergy Half of the people who use this term likely