3 ms·
At the same time it allows exploit writers to quickly add this to their kits. I'd expect AV vendors to already have signatures for this given that it's being a
by besselheim 10y ago
At the same time it allows exploit writers to quickly add this to their kits.
I'd expect AV vendors to already have signatures for this given that it's being actively exploited, which means there must be malware samples to know this.
- anfedorov 10y agoMost importantly it tells MS "fix your shit when your users are being attacked". Seven days ago was a Monday. That means they had a full week and a weekend to fix this. I understand that big bureaucratic organizations move slowly, and that the fix isn't trivial, but this is really the kind of thing for which they should have "scramble the jets and fix it" processes in place if they care about their user's security. When there are known exploits attacks against users, giving a short time to get out quick patches to trusted software vendors makes a lot of sense, but I don't see a good reason for giving more than 24-48 hours before public disclosure.
- ascendantlogic 10y agoAh yes, the endless holy war over what constitutes "responsible" disclosure and the concern over who benefits more, the attackers or the attackees? In this case, the exploit was being actively used in the wild. That means bad actors already had access to this and it was the users who were in the dark. Now it may be added to the "toolkits" of scripters and people who buy exploit frameworks but the people who do real damage were already using it according to Google.