3 ms·
The problem is that Google also said this: > The Windows vulnerability is a local privilege escalation in the Windows kernel that can be used as a security san
by besselheim 10y ago
The problem is that Google also said this:
> The Windows vulnerability is a local privilege escalation in the Windows kernel that can be used as a security sandbox escape. It can be triggered via the win32k.sys system call NtSetWindowLongPtr() for the index GWLP_ID on a window handle with GWL_STYLE set to WS_CHILD.
Which is enough information for someone to write an exploit from scratch.
If they'd just said there is a win32k.sys vulnerability and advised users to make sure Flash is up to date, this would have been fine.
- protomyth 10y agoI'm starting to believe the base problem is a difference between a software company that has to test the heck out of every patch because of their large customer base (Microsoft) and a company that doesn't have a complete consumer facing experience[1] (Google). Seven days is not enough to patch anything that needs to be tested in the extensive manner required. An update / disable Flash would have been good enough until a proper patch on the day IT has planned (Patch Tuesday) activities around the deployment of patches. I'm starting to think the ultimate PC OS for IT would be one with a transactional audit trail on all changes to the PC. 1) try calling Google about a problem if you disagree with this statement