Unsolved

This post is more than 5 years old

12 Elder

 • 

45.2K Posts

 • 

172.6K Points

11371

January 19th, 2015 12:00

Google reveals another Windows flaw

The new issue is an impersonation check bypass that could be an issue if a service is vulnerable to a named pipe planting attack or is storing encrypted data in a world readable shared memory section...

This is the second time in a week that Google has made a Windows security issue public, despite Microsoft working to correct the flaw, and asking Google to delay disclosure...

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

January 19th, 2015 15:00

I'm going to come out in favor of Microsoft --- and against Google --- in this case:

Google's "Project Zero" --- to publicly reveal vulnerabilities they discover --- insists it will invariably act using a rigid release date of 90 days after notifying the vendor [Microsoft].

Per the article, Microsoft was aware of the issue no later than 29 October 2014.   It's not that Microsoft was ignoring Google's threat/timeline --- indeed, it was working on a patch, and tentatively planned to release a fix as part of 13 January's Windows Updates.

As we are all painfully aware, Microsoft has released some "doozy" patches the past few months, and has been rightly criticized for doing so.

As part of their attempt to reinstate quality control, Microsoft discovered that their planned patch indeed had compatibility issues with various configurations, and so it would be premature/problematic to release it by the [artificial] deadline.

But Google stood firm in its ultimatum:   Microsoft could either go ahead and release a faulty patch that they knew could "bork" some/many computer systems, or they could take more time to fix the problem correctly --- while Google released the details so that hackers could take advantage of the exploit in the interim!   This was clearly a lose-lose situation for the public.   And its fate was entirely in Google's hands.

Had Microsoft ignored Google and not been working on a patch, Google would have every right to release the information per its announced time schedule.   But knowing that Microsoft WAS working on a patch --- that indeed, they THOUGHT they had a patch, which unfortunately proved to be problematic --- there was no earth-shaking reason why Google HAD to expose the vulnerability now... they just wanted to shove a big "GOTCHA!" into Microsoft's face.    Consequently, WE (the public) will suffer.

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

January 19th, 2015 15:00

My reply/comments above were based entirely on the article to which Ron linked.

However, looking further, I now see that Microsoft  **DID**  release MS15-003:   Vulnerability in Windows User Profile Service Could Allow Elevation of Privilege (3021674), to address [the only mentioned] vulnerability CVE-2015-0004, on 13 January.

Hmm... Something is mixed-up... or was that the EARLIER vulnerability that Google exposed publicly 2 days before Microsoft released its patch???

EDIT:   Yes, CVE-2015-0004 was an older vulnerability, NOT the one announced in the article.   I don't believe the newer vulnerability has been assigned a CVE reference number yet.   So I stand by my analysis above.

12 Elder

 • 

45.2K Posts

 • 

172.6K Points

January 20th, 2015 11:00

I wasn't taking sides in this...just reporting and quoting from that article.

We'll leave it to Microsoft and Google to point fingers at each other. Always amusing to watch their antics! :emotion-4:

And hopefully, it leads to better software security...

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

January 21st, 2015 09:00

It's one thing for Google to publicly "announce" the discovery/existence of a vulnerability... getting "credit" for it...

it's a completely different matter/motive to additionaly publish the proof-of-concept code to demonstrate how to exploit the vulnerability, effectively [offering] a blueprint for online criminals to launch attacks against [innocent/unprotected] Windows users, and allow [the criminals] to gain access to a user’s data in unencrypted form.

http://blog.lumension.com/9721/dont-be-evil-google-discloses-yet-another-zero-day-vulnerability-in-microsoft-code/ 

No Events found!

Top