Google warns of Windows zero-day under active exploit

By
Follow google news

Microsoft yet to issue patch.

Google is warning of a critical vulnerability in current versions of Windows that is unpatched and under active exploit by attackers.

Google warns of Windows zero-day under active exploit

Threat Analysis Group engineers Neel Mehta and Billy Leonard said Google had reported the flaw to Microsoft on October 22 (Australian time). 

As Microsoft has not issued an advisory or fix for the vulnerability, Mehta and Leonard disclosed its existence as per Google's policy.

"This vulnerability is particularly serious because we know it is being actively exploited," the pair wrote.

The flaw exists in the Windows operating system kernel, and comprises a local privilege escalation that allows attackers to escape the security sandboxn.

Google's Chrome browser mitigates against the exploit by blocking win32k.sys system calls, which prevents the flaw being used to escape the sandbox.

Mehta and Leonard also reported a zero-day vulnerability to Adobe at the same time as they contacted Microsoft. Adobe issued an emergency patch for the CVE-2016-7855 on October 27 (Australian time).

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

Health and Aged Care CISO retires

Health and Aged Care CISO retires

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Log In

  |  Forgot your password?