Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Google Discloses Another Unpatched Windows Vulnerability, Edge Users at Risk
#1
http://news.softpedia.com/news/google-di...3298.shtml    Google Discloses Another Unpatched Windows Vulnerability, Edge Users at Risk

Security flaw found in Microsoft Edge and Internet Explorer
Feb 25, 2017 05:56 GMT   By Bogdan Popa    
Google has published the details of another unpatched Windows security flaw, as per the company’s Project Zero program policy that discloses vulnerabilities still not fixed 90 days after the vendor is notified.

This time, the vulnerability is a type confusion in a module in Microsoft Edge and Internet Explorer, with Google engineer Ivan Fratric publishing a proof of concept that can crash the browsers, opening the door for potential attackers to gain administrator privileges on the affected systems.

Fratric says he made the analysis on the 64-bit version of Internet Explorer on Windows Server 2012 R2, but both 32-bit Internet Explorer 11 and Microsoft Edge should be affected by the same vulnerability. This means that Windows 7, Windows 8.1, and Windows 10 users are all exposed.

The vulnerability was reported on November 25, and according to Google Project Zero’s policy, it went public on February 25, as Microsoft is yet to deliver a patch.

Interestingly, Microsoft has already delayed this month’s Patch Tuesday cycle and is now planning to release security updates on March 14, but it’s not yet known if the company actually included a patch for this vulnerability discovered by Google in this month’s rollout or not.

Second public disclosure this month
This is the second security flaw disclosed by Google in just a couple of weeks, as the search company also published the details of a vulnerability in gdi32.dll that was first reported to Microsoft in March 2016.

Google Project Zero member Mateusz Jurczyk says Microsoft attempted to patch the flaw in June 2016, but the problem was only partially resolved, so another report was submitted to the firm in November 2016. Again, after the 3-month window expired, Jurczyk published details online.

This brings us to two different security vulnerabilities that are yet to be patched by Microsoft and whose details were posted online by Google, and it’s hard to believe that Redmond would turn to out-of-band fixes to address them before the March 14 rollout.

In the meantime, in order to remain protected against this new flaw, users are recommended to avoid clicking on websites they do not trust and to replace Internet Explorer and Microsoft Edge with a different browser if possible.

#Microsoft#Microsoft Edge#Internet Explorer#Google Project Zero#Windows 10
Reply
#2
IE and Edge has been replaced on my machine quite a while ago Wiggle
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Kaspersky discloses iPhone hardware feature vital in Operation Triangulation case mrtrout 0 983 12-31-2023 , 08:38 AM
Last Post: mrtrout
  Atlas VPN zero-day vulnerability leaks users' real IP address mrtrout 0 647 09-06-2023 , 08:42 AM
Last Post: mrtrout
  Anonymous urges Internet users to spam Google Maps, Bjyda 0 1,672 03-01-2022 , 09:13 PM
Last Post: Bjyda
  Volvo Cars discloses security breach leading to R&D data theft mrtrout 0 869 12-11-2021 , 12:25 AM
Last Post: mrtrout
  Microsoft and Google release urgent browser security update for Risk Level 4 Drive-b mrtrout 0 908 08-23-2021 , 09:13 AM
Last Post: mrtrout



Users browsing this thread: 2 Guest(s)