Customs Today
  • Home
  • Islamabad
  • Karachi
  • Lahore
  • National
  • Transfers and Postings
  • Chambers & Associations
  • Business
No Result
View All Result
Customs Today
  • Home
  • Islamabad
  • Karachi
  • Lahore
  • National
  • Transfers and Postings
  • Chambers & Associations
  • Business
No Result
View All Result
Customs Today
No Result
View All Result
Home Uncategorized

Google ignores Microsoft’s calls for flexible vulnerability, releases details of unpatched Windows flaw

byCustoms Today Report
16/01/2015
in Uncategorized
Share on FacebookShare on Twitter

NEW YORK: Google ignored Microsoft’s calls for flexible vulnerability disclosure deadlines and released details of another unpatched Windows flaw, leaving users exposed for at least the next 25 days.

The new vulnerability, which was confirmed on Windows 7 and 8.1, might constitute a security feature bypass for the way applications can encrypt their memory so that data can be exchanged between processes running under the same logon session.

You might also like

Pakistan to get $3b loan from Islamic Trade Financing Corporation

20/10/2024

Lahore I&I & Enforcement anti-smuggling operations achieve record success in early FY 2024-25

10/09/2024

“The issue is the implementation in CNG.sys doesn’t check the impersonation level of the token when capturing the logon session id (using SeQueryAuthenticationIdToken) so a normal user can impersonate at Identification level and decrypt or encrypt data for that logon session,” the Google Project Zero researchers said in a description of the flaw. “This might be an issue if there’s a service which is vulnerable to a named pipe planting attack or is storing encrypted data in a world readable shared memory section.”

According to Project Zero, Microsoft was notified of the vulnerability on Oct. 17 and initially planned to fix it during its January Patch, three days ago. However, the fix had to be postponed because of compatibility issues.

The Google researchers were unmoved by this and stuck to their 90-day public disclosure deadline, publishing details of the flaw and a proof-of-concept exploit.

The fix is now expected to be among Microsoft’s scheduled security updates on Feb. 10, although there’s no guarantee that it won’t be further delayed. Of course, Microsoft has the option to release an out-of-band patch at any time, but the company rarely does this and when it does, it’s typically for critical flaws that attackers are actively exploiting.

This is the third unpatched Windows vulnerability that Project Zero researchers have publicly disclosed over the past month because Microsoft could not issue fixes before the 90-day disclosure deadline enforced by Google.

Microsoft publicly denounced Google’s inflexibility with vulnerability disclosure, arguing that researchers should work with affected companies until a fix is produced before going public.

“We believe those who fully disclose a vulnerability before a fix is broadly available are doing a disservice to millions of people and the systems they depend upon,” Chris Betz, senior director with Microsoft’s Security Response Centre, said in a blog post at the time.

However, other researchers feel that 90 days is more than enough for a software vendor, especially one the size of Microsoft, to fix vulnerability.

Microsoft is just “whining” over its own inability to respond to bugs in a timely manner after over a decade of using its dominant position to dictate how vulnerabilities should be handled, said Robert Graham, the CTO of security research firm Errata Security in a blog post. “It’s now Google who sets the industry’s standard for reporting vulnerabilities,” he said.

Tags: Google ignores Microsoft’s calls for flexible vulnerabilityreleases details of unpatched Windows flaw

Related Stories

Pakistan to get $3b loan from Islamic Trade Financing Corporation

byCT Report
20/10/2024

ISLAMABAD: Islamic Trade Financing Corporation (ITFC) to provide Pakistan with a $3 billion loan, according to an official statement released...

Lahore I&I & Enforcement anti-smuggling operations achieve record success in early FY 2024-25

byCT Report
10/09/2024

LAHORE:  Regional Directorate of Customs Intelligence & Investigation has demonstrated exceptional performance in the first two months of the fiscal...

ICCI and CDA to join hands for tree plantation drive in Capital

byQaisar Mansoor
09/08/2023

ISLAMABAD: Islamabad Chamber of Commerce and Industry (ICCI) in collaboration with the Capital Development Authority (CDA) would jointly launch a...

Customs Officials Yawar Abbas & Tariq Mehmood kidnapped in Karachi

byCT Report
08/07/2023

KARACHI: Customs Intelligence Officer Yawar Abbas and Customs Preventive Officer Tariq Mehmood who were working against smuggling were kidnapped by...

Next Post

New Zealand's Kea Petroleum to shut production at Puka Field site in Taranaki

  • Terms and Conditions
  • Disclaimer

© 2011 Customs Today -World's first newspaper on customs. Customs Today.

No Result
View All Result
  • Transfers and Postings
  • Latest News
  • Karachi
  • Islamabad
  • Lahore
  • National
  • Chambers & Associations
  • Business
  • About Us

© 2011 Customs Today -World's first newspaper on customs. Customs Today.