Google Reveals Actively Exploited Windows Kernel Vulnerability

Google disclosed two actively exploited vulnerabilities seven days after revealing them to the relevant vendors, which in this case are Adobe and Microsoft. Google said that Adobe has already fixed its bug, but that Microsoft hasn’t released an advisory or fix yet.

Latest Videos FromTom's Hardware
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • ah
    My windows updated Flash security on 28 Oct, but I don't think it also included the windows bug fix.
    Reply
  • alextheblue
    They gave them a week to patch (and test for issues) a kernel-level vulnerability before disclosing? Yikes.
    Reply
  • bit_user
    I wish Google would run their security tests on this:

    https://www.reactos.org

    If it passes, I'd probably give it a try.
    Reply
  • Paladiam
    More like Government back door access found.
    Reply
  • hst101rox
    Is Windows XP vulnerable? I'm going to assume "Yes!"
    Reply
  • Tanyac
    I'm wondering, given Microsoft's new "monthly" patch cycle whether they will even both to do anything until the November patch release.

    Since Microsoft has clearly demonstrated with recent policy changes that customer safety, satisfaction and sanity are the least important things to them I'd not be surprised if we don't see a patch for at least another week, maybe more...
    Reply
  • Jan_26
    A week for implementation, testing, validation and signing of a change in kernel is plain insanity.
    Reply
  • WFang
    18807656 said:
    They gave them a week to patch (and test for issues) a kernel-level vulnerability before disclosing? Yikes.

    18808184 said:
    A week for implementation, testing, validation and signing of a change in kernel is plain insanity.

    Guys, NOT disclosing details of a vulnerability that is ACTIVELY being exploited in the wild is a far greater insanity!
    Sure, you can easily argue that any sane find+patch+Quality Control cycle on such a bug would be more than 7 days, that is rather irrelevant. It is MUCH more important to get the warning out to IT and SysAdmins (of critical infrastructure and functions).

    It's like complaining about how it is 'plain insanity' to expect fire-fighters to completely put out and control a fire in a 40 story hotel within 1 hour and that therefore one should not alert new and existing guests of the hotel that there is, in fact, a fire going on. "Nah, let them into the lobby man, the firefighters only had an hour to work on this, no reason to alert anyone just yet"...

    Clearly, it would take longer to put out such a fire; and clearly, all the guests and prospecting guests need to be alerted ASAP.
    The two actions are not mutually exclusive!
    Reply
  • gggplaya
    18807656 said:
    They gave them a week to patch (and test for issues) a kernel-level vulnerability before disclosing? Yikes.

    They give 90 days to lower risk and lower actively exploited vunerabilities. But for high risk and highly actively exploited attacks, they only give 7 days and light a fire under microsofts butt to fix it. Otherwise, microsoft might be relaxed and wait the full 90 days to fix it. Leaving us consumers under attack for the full 3 months.
    Reply
  • coolitic
    As much as I dislike security flaws, I disapprove of Google taking a strong-arm approach to force companies to fix them.
    Reply