Android Century
  • Home
  • Android Zone
    • Android Apps
    • Android Games
    • Apps APk Files
    • Games Apk Files
    • Apps Hack Tricks
  • Reviews
  • Fantasy Zone
    • Entertainment
    • Quotes and Status
    • Life Style
    • Home Made Tips
    • Hair Care
    • Skin Care
    • Fantasy Tips
  • Tricks
    • Free Recharge
    • Free Internet
    • shopping Cashback
    • Recharge Cashback
  • Tech
  • Mobiles
  • Gadgets
  • News
  • How To's
  • Software
Breaking
Loading...

Featured post

How to Take Great Photos With Apple's iPhone X

Recent Posts

Labels

  • Android Apk Files
  • Android Apps
  • Android Games
  • Apps Apk Files
  • Entertainment
  • Fantasy Tips
  • Gadgets
  • Hair Care
  • HomeMade Tips
  • How To's
  • News
  • Quotes
  • Quotes & Status
  • Recharge Cashback
  • Recharge Promo Codes
  • Shopping Cashback
  • Technology
  • skin care
Home / News / Google discloses unpatched IE vulnerability after Patch Tuesday delay

Google discloses unpatched IE vulnerability after Patch Tuesday delay

Latest Govt. Jobs 16:09:00 News Edit
microsoft stock campus building

Google's Project Zero team has disclosed a potential arbitrary code execution vulnerability in Internet Explorer because Microsoft has not acted within Google's 90-day disclosure deadline.
This is the second flaw in Microsoft products made public by Google Project Zero since the Redmond giant decided to skip this month's Patch Tuesday and postpone its previously planned security fixes until March.
Microsoft blamed the unprecedented decision to push back scheduled security updates by a month on a "last minute issue" that could have had an impact on customers, but the company hasn't clarified the nature of the problem.
Some people have speculated that the problem might be related to the Windows Update infrastructure and not a particular fix, but the company pushed out a Flash Player security update on Tuesday, which suggests that if there was an infrastructure problem, it is now resolved.
The newly disclosed vulnerability is a so-called type confusion flaw that affects Microsoft Edge and Internet Explorer and can potentially allow remote attackers to execute arbitrary code on the underlying system.
"No exploit is available, but a PoC [proof-of-concept] demonstrating a crash is," Carsten Eiram, chief research officer at vulnerability intelligence firm Risk Based Security, said via email. "This PoC may provide a good starting point for anyone who wants to develop a working exploit. Google [Project Zero] even includes some comments on how to possibly achieve code execution."
The Risk Based Security researchers have confirmed the potentially exploitable crash for IE11 on a fully patched Windows 10 system and have assigned a CVSS severity score of 6.8 to it, treating its impact as potential code execution.
On Feb. 14, after Microsoft announced its decision to postpone the February patches, Google Project Zero disclosed a memory disclosure vulnerability in Windows' GDI library.
Another vulnerability that has yet to be patched was publicly disclosed three weeks ago by an independent researcher. The flaw is located in Microsoft's implementation of the SMB network file-sharing protocol and can be exploited to crash Windows computers if attackers trick them into connecting to rogue SMB servers. The researcher who disclosed the vulnerability claimed Microsoft intended to patch it in February.
So, at the moment there are three zero-day vulnerabilities in Microsoft products that the company might have planned to patch on Feb. 14 but didn't. Some security researchers, including Eiram, believe Microsoft should release the patches it has now instead of waiting.
"Even if no exploits are currently available, Microsoft is gambling with their users' security," Eiram said. "If exploits do suddenly surface, Microsoft would likely have to release out-of-band security updates anyway, forcing customers to scramble to apply these fixes. It makes more sense to handle it in a proactive manner."
Software vendors' commitment to monthly patch cycles is understandable as it serves their customers' need to have some predictability about when security updates will need to be applied. However, Eiram believes that sticking to these cycles should never have a higher priority than getting security fixes out in a timely manner.
"Microsoft has always reserved the right to release out-of-band security updates when necessary, and even with no exploits available it is necessary now," he said. "There are three known, unpatched vulnerabilities and at least one of them has code execution potential."
Share on Facebook Share on Twitter Share on Google Plus

RELATED POSTS


Vivo V9 with dual rear cameras

Xiaomi Redmi 5 launch

Vodafone partners with Tecno to off...
Google discloses unpatched IE vulnerability after Patch Tuesday delay Google discloses unpatched IE vulnerability after Patch Tuesday delay Reviewed by Latest Govt. Jobs on 16:09:00 Rating: 5

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments ( Atom )

Search This Blog

TEST BOOK FOR GOVT ENTRANCE TEST

TEST BOOK FOR GOVT ENTRANCE TEST
Find All Latest book for preparation of SSC,RAILWAYBANK PO,RBI,BANK CLERK,GATE ME,GATE CE are available here in less prices, to check out the books click here

Translate

  • Popular Post
  • Random posts
  • Category

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & Earn Offer:  Hey Guys! Today I make an article about Teen Patti Referral ...
  • Taotronics TT-BH22 Headphones Review
    We make it a addiction to now not look up pricing of a product sooner than reviewing and if ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on Monday strongly condemned North Korea’s latest missile test, adding that the ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows 10 Creators Update is here, now—yes,  now —but not (officially) on the PC. The ...
  • Fitbit Zip 2017 review
    Fitbit PROS: Clever, accurate tracking Expandable online service Integration with 3rd ...

Random Posts

  • Google Play Music: The Ultimate Guide 2017
    Google Play Music: The Ultimate Guide 2017
    14.01.2017 - 0 Comments
    There is more music than you can imagine right at your fingertips. While there are many apps that stream…
  • Zelda: Breath of the Wild patch gives huge framerate upgrades
    Zelda: Breath of the Wild patch gives huge framerate upgrades
    31.03.2017 - 0 Comments
    Nintendo's back with a bang, with The Legend of Zelda: Breath of the Wild garnering…
  • The best add-ons for the Kodi media player and how to install them
    The best add-ons for the Kodi media player and how to install them
    11.03.2017 - 0 Comments
    Kodi, the versatile open source media player has a lot of hidden talents thanks to its huge…
  • All new iOS apps need to support iPhone X’s display
    All new iOS apps need to support iPhone X’s display
    16.02.2018 - 0 Comments
    Apple’s email to iOS developers: All new iOS apps need to support iPhone X’s display. (Apple iPhone X is…
  • Moto X4 specifications leaked
    Moto X4 specifications leaked
    12.08.2017 - 0 Comments
    Image courtesy: Android Authority Motorola's Moto X range of smartphones have created…

Labels

Android Apk Files Android Apps Android Games Apps Apk Files Apps Hack Tricks Entertainment Free Internet Freecharge Gadgets Games Apk Files How To's Laptops Guide Mobiles Reviews Technology Viral's android zone free recharge

Entertainment

Tricks

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows ...
  • Taotronics TT-BH22 Headphones Review
    We make it a ...
  • Latest Blackberry KEYone on website, spills out price and other details
    China-based  ...
  • Paytm Hostel Booking Offer HTL40 – Get 40% cashback On No Minimum Order Value (2 Times)
    Paytm Paytm Hostel ...
  • RBI's cellular wallet interoperability faces few hurdles
    Adding a new ...
  • Here Government launches cyber security services to keep you safe from malware
    The  Indian ...

Random Posts

  • Sony a9 (ILCE-9) Review
    Sony a9 (ILCE-9) Review
    06.01.2018 - 0 Comments
    Of late a lot of photographers and those engaged in video production have been moving to…
  • Xiaomi launches Mi 5c phone with in-house 8-core Surge S1 processor
    Xiaomi launches Mi 5c phone with in-house 8-core Surge S1 processor
    28.02.2017 - 0 Comments
    Xiaomi, on Tuesday, became only the fourth smartphone manufacturer in the world - and…
  • How to switch from Mac to PC, Part 1: What's driving me to do it
    How to switch from Mac to PC, Part 1: What's driving me to do it
    14.02.2017 - 0 Comments
    After nearly 20 years as a Mac user, I’m switching to a Windows PC—and I’m bringing you along for the…
  • How can you Remove Password From PDF File
    How can you Remove Password From PDF File
    11.04.2017 - 0 Comments
    Some PDFs are encrypted with a password, which you’ll need to enter each time you want to view…
  • Apollo 11's crew capsule is going on a four-city tour
    Apollo 11's crew capsule is going on a four-city tour
    26.02.2017 - 0 Comments
    On July 20, 1969, the Apollo 11 mission successfully delivered the first humans to the surface of the…

Most Popular

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J ...
  • Top 5 Best SmartPhones under 7000 Rs (March 2017)
    Looking for the ...
  • Apple, IBM, Cisco are huge because of Indians, do not deny them H-1B visa: RBI Governor Urjit Patel
    ...
  • SAMSUNG GALAXY J7 (2016) Specifications
    SAMSUNG GALAXY J ...
  • BlackBerry Teases Marshmallow Beta Testing for Priv by Next Week
    Blackberry ...
  • LG Q6 Review
    LG Q6 Review
    2017 is ...

Contact Form

Name

Email *

Message *

Offers Zone

Created By Android Century Distributed by Android Century
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms of use
  • Advertise here
Subscribe Via Email Subscribe To Android Century By Email And Get Free Updates. ;-)


Your email address is safe with us!