Android Century
  • Home
  • Android Zone
    • Android Apps
    • Android Games
    • Apps APk Files
    • Games Apk Files
    • Apps Hack Tricks
  • Reviews
  • Fantasy Zone
    • Entertainment
    • Quotes and Status
    • Life Style
    • Home Made Tips
    • Hair Care
    • Skin Care
    • Fantasy Tips
  • Tricks
    • Free Recharge
    • Free Internet
    • shopping Cashback
    • Recharge Cashback
  • Tech
  • Mobiles
  • Gadgets
  • News
  • How To's
  • Software
Breaking
Loading...

Featured post

How to Take Great Photos With Apple's iPhone X

Recent Posts

Labels

  • Android Apk Files
  • Android Apps
  • Android Games
  • Apps Apk Files
  • Entertainment
  • Fantasy Tips
  • Gadgets
  • Hair Care
  • HomeMade Tips
  • How To's
  • News
  • Quotes
  • Quotes & Status
  • Recharge Cashback
  • Recharge Promo Codes
  • Shopping Cashback
  • Technology
  • skin care
Home / News / Google discloses unpatched IE vulnerability after Patch Tuesday delay

Google discloses unpatched IE vulnerability after Patch Tuesday delay

Latest Govt. Jobs 16:09:00 News Edit
microsoft stock campus building

Google's Project Zero team has disclosed a potential arbitrary code execution vulnerability in Internet Explorer because Microsoft has not acted within Google's 90-day disclosure deadline.
This is the second flaw in Microsoft products made public by Google Project Zero since the Redmond giant decided to skip this month's Patch Tuesday and postpone its previously planned security fixes until March.
Microsoft blamed the unprecedented decision to push back scheduled security updates by a month on a "last minute issue" that could have had an impact on customers, but the company hasn't clarified the nature of the problem.
Some people have speculated that the problem might be related to the Windows Update infrastructure and not a particular fix, but the company pushed out a Flash Player security update on Tuesday, which suggests that if there was an infrastructure problem, it is now resolved.
The newly disclosed vulnerability is a so-called type confusion flaw that affects Microsoft Edge and Internet Explorer and can potentially allow remote attackers to execute arbitrary code on the underlying system.
"No exploit is available, but a PoC [proof-of-concept] demonstrating a crash is," Carsten Eiram, chief research officer at vulnerability intelligence firm Risk Based Security, said via email. "This PoC may provide a good starting point for anyone who wants to develop a working exploit. Google [Project Zero] even includes some comments on how to possibly achieve code execution."
The Risk Based Security researchers have confirmed the potentially exploitable crash for IE11 on a fully patched Windows 10 system and have assigned a CVSS severity score of 6.8 to it, treating its impact as potential code execution.
On Feb. 14, after Microsoft announced its decision to postpone the February patches, Google Project Zero disclosed a memory disclosure vulnerability in Windows' GDI library.
Another vulnerability that has yet to be patched was publicly disclosed three weeks ago by an independent researcher. The flaw is located in Microsoft's implementation of the SMB network file-sharing protocol and can be exploited to crash Windows computers if attackers trick them into connecting to rogue SMB servers. The researcher who disclosed the vulnerability claimed Microsoft intended to patch it in February.
So, at the moment there are three zero-day vulnerabilities in Microsoft products that the company might have planned to patch on Feb. 14 but didn't. Some security researchers, including Eiram, believe Microsoft should release the patches it has now instead of waiting.
"Even if no exploits are currently available, Microsoft is gambling with their users' security," Eiram said. "If exploits do suddenly surface, Microsoft would likely have to release out-of-band security updates anyway, forcing customers to scramble to apply these fixes. It makes more sense to handle it in a proactive manner."
Software vendors' commitment to monthly patch cycles is understandable as it serves their customers' need to have some predictability about when security updates will need to be applied. However, Eiram believes that sticking to these cycles should never have a higher priority than getting security fixes out in a timely manner.
"Microsoft has always reserved the right to release out-of-band security updates when necessary, and even with no exploits available it is necessary now," he said. "There are three known, unpatched vulnerabilities and at least one of them has code execution potential."
Share on Facebook Share on Twitter Share on Google Plus

RELATED POSTS


Vivo V9 with dual rear cameras

Xiaomi Redmi 5 launch

Vodafone partners with Tecno to off...
Google discloses unpatched IE vulnerability after Patch Tuesday delay Google discloses unpatched IE vulnerability after Patch Tuesday delay Reviewed by Latest Govt. Jobs on 16:09:00 Rating: 5

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments ( Atom )

Search This Blog

TEST BOOK FOR GOVT ENTRANCE TEST

TEST BOOK FOR GOVT ENTRANCE TEST
Find All Latest book for preparation of SSC,RAILWAYBANK PO,RBI,BANK CLERK,GATE ME,GATE CE are available here in less prices, to check out the books click here

Translate

  • Popular Post
  • Random posts
  • Category

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & Earn Offer:  Hey Guys! Today I make an article about Teen Patti Referral ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows 10 Creators Update is here, now—yes,  now —but not (officially) on the PC. The ...
  • Taotronics TT-BH22 Headphones Review
    We make it a addiction to now not look up pricing of a product sooner than reviewing and if ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on Monday strongly condemned North Korea’s latest missile test, adding that the ...
  • Bank wallets growing faster than e-wallets
    In the  bank  versus  e-wallets  sweepstakes,  lenders  have now gained lost ground. As of ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...

Random Posts

  • Moto G5S Plus, Moto G5S and more receives a price cut in India
    Moto G5S Plus, Moto G5S and more receives a price cut in India
    14.02.2018 - 0 Comments
    NEW DELHI: Its raining offers this Valentine's Day. The leading e-commerce player Amazon is giving…
  • How to Secure Your Accounts With a U2F Key
    How to Secure Your Accounts With a U2F Key
    11.02.2017 - 0 Comments
    U2F is an emerging standard for physical authentication tokens. Current U2F keys are all small…
  • Demonetisation: Wallet Companies Are Expanding, but Where Is UPI?
    Demonetisation: Wallet Companies Are Expanding, but Where Is UPI?
    15.11.2016 - 0 Comments
    HIGHLIGHTS UPI allows you simple net banking without IFSC codes, account numbers It's as easy as…
  • How to book a holiday online: best holiday tips, packages, DIY, websites and apps
    How to book a holiday online: best holiday tips, packages, DIY, websites and apps
    11.02.2017 - 2 Comments
    No matter what time of year it is, we’re all thinking about jetting off somewhere. Even if we tend to…
  • Brand Really Matter When Buying a Hard Drive
    Brand Really Matter When Buying a Hard Drive
    12.03.2017 - 0 Comments
    When it comes to hard drives, everyone seems to have a horror story about one brand or another that…

Labels

Android Apk Files Android Apps Android Games Apps Apk Files Apps Hack Tricks Entertainment Free Internet Freecharge Gadgets Games Apk Files How To's Laptops Guide Mobiles Reviews Technology Viral's android zone free recharge

Entertainment

Tricks

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows ...
  • Meet Bat Bot, the new flying batlike drone
    Holy drone ...
  • Lenovo Yoga Book launched in India at Rs 49,990: First Impressions
    Lenovo  has ...
  • Donald Trump presidency gets social with detailed posts, photos
    US President ...
  • Jio effect: Telcos may have to cut data rates 2017
    India's big  ...
  • Grow Hair Faster: How to Make Hair Grow Faster Naturally
    Every woman wants ...

Random Posts

  • How to download and install the Kodi Krypton 17 update
    How to download and install the Kodi Krypton 17 update
    10.02.2017 - 0 Comments
    Kodi 17.0, also known as ‘Krypton’, has now been released . This update to the popular…
  • Quotes
    Quotes
    02.04.2016 - 0 Comments
  • Nintendo's 'Miitomo' to close in May
    Nintendo's 'Miitomo' to close in May
    27.01.2018 - 0 Comments
    Its first foray into the world of smartphone software, Nintendo will be closing atypical social…
  • Nokia 8 starts receiving Android 8.1 Oreo
    Nokia 8 starts receiving Android 8.1 Oreo
    15.02.2018 - 0 Comments
    Nokia 8 has started receiving Android 8.1 Oreo update. Nokia 8 has started…
  • Huawei Mate 9 Review: The Best Galaxy Note 7 Alternative Around
    Huawei Mate 9 Review: The Best Galaxy Note 7 Alternative Around
    11.02.2017 - 0 Comments
    The Huawei Mate 8, which launched in 2015, was an all round good egg of a phone, but it really blew us…

Most Popular

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J ...
  • Top 5 Best SmartPhones under 7000 Rs (March 2017)
    Looking for the ...
  • Apple, IBM, Cisco are huge because of Indians, do not deny them H-1B visa: RBI Governor Urjit Patel
    ...
  • SAMSUNG GALAXY J7 (2016) Specifications
    SAMSUNG GALAXY J ...
  • BlackBerry Teases Marshmallow Beta Testing for Priv by Next Week
    Blackberry ...
  • LG Q6 Review
    LG Q6 Review
    2017 is ...

Contact Form

Name

Email *

Message *

Offers Zone

Created By Android Century Distributed by Android Century
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms of use
  • Advertise here
Subscribe Via Email Subscribe To Android Century By Email And Get Free Updates. ;-)


Your email address is safe with us!