Jump to content

Google and MicroSoft butt heads again over disclosing seccurity vulnerability

zMeul

Microsoft says in a statement that the security issue reported by Google was actually already fixed for Windows 10 Anniversary Update users.

 

Neowin says:

Quote

Myerson said that a group called STRONTIUM performed a spear-phishing attack, but before we go any further, users on the Windows 10 Anniversary Update using the Edge browser should already be protected from it. It used two zero-day vulnerabilities in Flash and the Windows kernel to do the following:

  1. Exploit Flash to gain control of the browser process

  2. Elevate privileges in order to escape the browser sandbox

  3. Install a backdoor to provide access to the victim’s computer

So it looks like other Windows users need to update Flash plug-in, or wait until Microsoft to get around to try and patch the exploit around Flash.

 

https://www.neowin.net/news/microsoft-responds-to-google-releasing-security-vulnerability-will-patch-it-next-week

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, GoodBytes said:

already fixed for Windows 10 Anniversary Update users

Only for those using Edge, it looks like they patched the OS vulnerability at the browser level.  Use any other browser and Win10 is about as secure as an open door in a ghetto.

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, Captain Chaos said:

Only for those using Edge, it looks like they patched the OS vulnerability at the browser level.  Use any other browser and Win10 is about as secure as an open door in a ghetto.

Update Flash?

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, GoodBytes said:

Update Flash?

The hole is in windows itself. Even if you update it nothing prevents hackers from exploiting it with different approach...9_9

Link to comment
Share on other sites

Link to post
Share on other sites

14 minutes ago, GoodBytes said:

Update Flash?

" a local privilege escalation in the Windows kernel "

 

The exploit may rely on Flash to trigger the escalation and the sandbox escape, but the vulnerability itself is in the Windows kernel.

 

While it's easier to patch Flash and the browser than it is to fix the kernel, it still leaves a vulnerability in the OS itself, one that hackers are aware of. 

What do you think is easier, finding a new way to exploit a known vulnerability or digging through an entire OS to find a new vulnerability? 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, GoodBytes said:

Update Flash?

The problem is that the underlying security hole (which allows for privilege escalation and is part of win32k.sys) is not patched. It's just that the exploit that is current out in the wild used Flash to take advantage of the hole. It might be possible to use some other attack vector to take advantage of the same security hole.

It means that a small security hole in flash, office, chrome, whatever, might go from a minor issue to a full blown, admin privilege, sandbox escaping exploit.

Link to comment
Share on other sites

Link to post
Share on other sites

Patching a kernel could take a lot more work than patching Flash. So if Microsoft needed more time than Adobe, I don't entirely blame them. But if it's true that they didn't even acknowledge Google's message, let alone ask for more time, well...

Link to comment
Share on other sites

Link to post
Share on other sites

8 hours ago, LAwLz said:

I was about to side with Microsoft on this, but assuming that it is true that Microsoft did not acknowledge it (as in, did not ask Google for more time nor made an effort to fix the issue as quickly as possible), and on top of that the fact that the exploit is/was already being used in the wild, I think Google did the right thing.

 

By the way, the exploit Google published relies on Flash to be executed in its current form. Since Adobe already released a patch it is kind of fixed. The problem is that the underlying issue (in Windows) is not yet fixed and it might be possible to use it without relying on Flash.

 

So it's not like Google just went "hey Microsoft, you got a security hole in Windows. <10 days later>. Lol, let's tell everyone about the security hole".

Supposedly,

1) Microsoft ignored/did not make an effort to fix the issue after Google told them about it.

2) The exploit was already being used, so attackers already knew about it.

3) Flash, which the exploit relied on had been fixed, so the attack in its current form does not work.

 

 

 

To do what? Find exploits in code? Plenty of people, organizations and companies ask Google to do it. Finding exploits is a great thing. It makes everyone more safe and secure.

Why should they ask for more time? This is unorthodox and frankly Google is asking to be sued at this point.

Judge a product on its own merits AND the company that made it.

How to setup MSI Afterburner OSD | How to make your AMD Radeon GPU more efficient with Radeon Chill | (Probably) Why LMG Merch shipping to the EU is expensive

Oneplus 6 (Early 2023 to present) | HP Envy 15" x360 R7 5700U (Mid 2021 to present) | Steam Deck (Late 2022 to present)

 

Mid 2023 AlTech Desktop Refresh - AMD R7 5800X (Mid 2023), XFX Radeon RX 6700XT MBA (Mid 2021), MSI X370 Gaming Pro Carbon (Early 2018), 32GB DDR4-3200 (16GB x2) (Mid 2022

Noctua NH-D15 (Early 2021), Corsair MP510 1.92TB NVMe SSD (Mid 2020), beQuiet Pure Wings 2 140mm x2 & 120mm x1 (Mid 2023),

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, AluminiumTech said:

Why should they ask for more time? This is unorthodox and frankly Google is asking to be sued at this point.

on what basis?

 

Or you seriously that blind of a fanboy?

One day I will be able to play Monster Hunter Frontier in French/Italian/English on my PC, it's just a matter of time... 4 5 6 7 8 9 years later: It's finally coming!!!

Phones: iPhone 4S/SE | LG V10 | Lumia 920 | Samsung S24 Ultra

Laptops: Macbook Pro 15" (mid-2012) | Compaq Presario V6000

Other: Steam Deck

<>EVs are bad, they kill the planet and remove freedoms too some/<>

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, suicidalfranco said:

on what basis?

 

Or you seriously that blind of a fanboy?

if Microsoft knows there's an issue, I can count on them to try and fix it. If Google knows there's an issue with one of their services, I can count on them to fix it.

 

There's no need to have such a big dramatic situation. they can work on a fix without starting world war 3.

 

 

Jesus. People these days.........

Judge a product on its own merits AND the company that made it.

How to setup MSI Afterburner OSD | How to make your AMD Radeon GPU more efficient with Radeon Chill | (Probably) Why LMG Merch shipping to the EU is expensive

Oneplus 6 (Early 2023 to present) | HP Envy 15" x360 R7 5700U (Mid 2021 to present) | Steam Deck (Late 2022 to present)

 

Mid 2023 AlTech Desktop Refresh - AMD R7 5800X (Mid 2023), XFX Radeon RX 6700XT MBA (Mid 2021), MSI X370 Gaming Pro Carbon (Early 2018), 32GB DDR4-3200 (16GB x2) (Mid 2022

Noctua NH-D15 (Early 2021), Corsair MP510 1.92TB NVMe SSD (Mid 2020), beQuiet Pure Wings 2 140mm x2 & 120mm x1 (Mid 2023),

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, suicidalfranco said:

on what basis?

 

Or you seriously that blind of a fanboy?

He is seriously that much of a fanboy. He actually hopes to have a job with MS at some point.

"We also blind small animals with cosmetics.
We do not sell cosmetics. We just blind animals."

 

"Please don't mistake us for Equifax. Those fuckers are evil"

 

This PSA brought to you by Equifacks.
PMSL

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, AluminiumTech said:

Why should they ask for more time? This is unorthodox and frankly Google is asking to be sued at this point.

"Dear sir, if you don't leave the toilet or tell us you're okay, we're gonna have to open the door and force you out, did you hear me? Sir?" - Google (waiter) vs Microsoft (the customer)

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Dabombinable said:

He is seriously that much of a fanboy. He actually hopes to have a job with MS at some point.

No I don't. If I happen to have a job with them in the future, then that will be fine. but it'd be just as happy to work for some other respected tech company.

 

1 minute ago, Tiuqu said:

"Dear sir, if you don't leave the toilet or tell us you're okay, we're gonna have to open the door and force you out, did you hear me? Sir?" - Google (waiter) vs Microsoft (the customer)

I don't see Microsoft showing Google all the flaws in Android.......

Judge a product on its own merits AND the company that made it.

How to setup MSI Afterburner OSD | How to make your AMD Radeon GPU more efficient with Radeon Chill | (Probably) Why LMG Merch shipping to the EU is expensive

Oneplus 6 (Early 2023 to present) | HP Envy 15" x360 R7 5700U (Mid 2021 to present) | Steam Deck (Late 2022 to present)

 

Mid 2023 AlTech Desktop Refresh - AMD R7 5800X (Mid 2023), XFX Radeon RX 6700XT MBA (Mid 2021), MSI X370 Gaming Pro Carbon (Early 2018), 32GB DDR4-3200 (16GB x2) (Mid 2022

Noctua NH-D15 (Early 2021), Corsair MP510 1.92TB NVMe SSD (Mid 2020), beQuiet Pure Wings 2 140mm x2 & 120mm x1 (Mid 2023),

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, AluminiumTech said:

if Microsoft knows there's an issue, I can count on them to try and fix it. If Google knows there's an issue with one of their services, I can count on them to fix it.

 

There's no need to have such a big dramatic situation. they can work on a fix without starting world war 3.

 

 

Jesus. People these days.........

they knew there was an issue after google told them, they decided to do jack shit to fix it. As simple as that.

The exploit was already being used by who knows what kind of people, might as well make it public and force MS to fix their shit. But no, please do tell me how this is wrong 

One day I will be able to play Monster Hunter Frontier in French/Italian/English on my PC, it's just a matter of time... 4 5 6 7 8 9 years later: It's finally coming!!!

Phones: iPhone 4S/SE | LG V10 | Lumia 920 | Samsung S24 Ultra

Laptops: Macbook Pro 15" (mid-2012) | Compaq Presario V6000

Other: Steam Deck

<>EVs are bad, they kill the planet and remove freedoms too some/<>

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, AluminiumTech said:

I don't see Microsoft showing Google all the flaws in Android.......

*spoilers*
THEY SHOULD.

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, AluminiumTech said:

No I don't. If I happen to have a job with them in the future, then that will be fine. but it'd be just as happy to work for some other respected tech company.

 

I don't see Microsoft showing Google all the flaws in Android.......

Cause Google already has a bounty program that rewards people who finds bug and security holes in Android and Chrome, also every bug reported by security firms and researchers get promptly patched and made public soon after  

One day I will be able to play Monster Hunter Frontier in French/Italian/English on my PC, it's just a matter of time... 4 5 6 7 8 9 years later: It's finally coming!!!

Phones: iPhone 4S/SE | LG V10 | Lumia 920 | Samsung S24 Ultra

Laptops: Macbook Pro 15" (mid-2012) | Compaq Presario V6000

Other: Steam Deck

<>EVs are bad, they kill the planet and remove freedoms too some/<>

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, GoodBytes said:

Microsoft says in a statement that the security issue reported by Google was actually already fixed for Windows 10 Anniversary Update users.

 

Neowin says:

So it looks like other Windows users need to update Flash plug-in, or wait until Microsoft to get around to try and patch the exploit around Flash.

 

https://www.neowin.net/news/microsoft-responds-to-google-releasing-security-vulnerability-will-patch-it-next-week

so MS actually fixed shit

Link to comment
Share on other sites

Link to post
Share on other sites

8 hours ago, zMeul said:

686px-Microsoft_logo_(1975).svg.png

 
Not signed in

Would be a bad brand for a product that's related to the genital area of men.

Strike the shepherd and the sheep will scatter.

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, AluminiumTech said:

Why should they ask for more time? This is unorthodox and frankly Google is asking to be sued at this point.

It's not unorthodox at all, in fact it's relatively common in the industry for researches to do. Vulnerability disclosure is very much a necessary thing and makes everyone better off http://www.heinz.cmu.edu/~rtelang/disclosure_jan_06.pdf

On what grounds would Google be sued? 

15" MBP TB

AMD 5800X | Gigabyte Aorus Master | EVGA 2060 KO Ultra | Define 7 || Blade Server: Intel 3570k | GD65 | Corsair C70 | 13TB

Link to comment
Share on other sites

Link to post
Share on other sites

14 minutes ago, Blade of Grass said:

On what grounds would Google be sued? 

on the grounds of fanboyism xD

 

@AluminiumTech Google's Project Zero runs since 2014, it's goal: finding zero-day exploits https://security.googleblog.com/2014/07/announcing-project-zero.html

remember the "Heartbleed" vulnerability? this is why the Project Zero was formed

Link to comment
Share on other sites

Link to post
Share on other sites

full disclosure is always the way to go imo, but something like this is obviously better for the company.

if they dont even acknowledge it within a decent timeframe, fuck them and release it.

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, OptimisticRealist said:

Wtf is that?

MicroSoft's logo from 1975, that was their logo when they were founded

Link to comment
Share on other sites

Link to post
Share on other sites

30 minutes ago, zMeul said:

MicroSoft's logo from 1975, that was their logo when they were founded

It is Microsoft, use modern logos FFS, or have you not known about Apple's first logo????

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×