3 ms·
The future patch that Google should have coordinated their disclosure with.
by besselheim 10y ago
The future patch that Google should have coordinated their disclosure with.
- Oletros 10y agoSo, there is no patch. And the only mitigating thing is what Google has said, patching Flash. Now, tell me, how users would know about that without disclosing. And, remember, there are already exploits
- besselheim 10y agoThe problem is that Google also said this: > The Windows vulnerability is a local privilege escalation in the Windows kernel that can be used as a security sandbox escape. It can be triggered via the win32k.sys system call NtSetWindowLongPtr() for the index GWLP_ID on a window handle with GWL_STYLE set to WS_CHILD. Which is enough information for someone to write an exploit from scratch. If they'd just said there is a win32k.sys vulnerability and advised users to make sure Flash is up to date, this would have been fine.
- protomyth 10y agoI'm starting to believe the base problem is a difference between a software company that has to test the heck out of every patch because of their large customer base (Microsoft) and a company that doesn't have a complete consumer facing experience[1] (Google). Seven days is not enough to patch anything that needs to be tested in the extensive manner required. An update / disable Flash would have been good enough until a proper patch on the day IT has planned (Patch Tuesday) activities around the deployment of patches. I'm starting to think the ultimate PC OS for IT would be one with a transactional audit trail on all changes to the PC. 1) try calling Google about a problem if you disagree with this statement