Jump to content
Sign in to follow this  
Half Monk

Windows systems attacked via vulnerability made public by Google engineer

Recommended Posts

Microsoft is saying that some PCs have been attacked with hackers taking advantage of a vulnerability that was originally revealed by a Google engineer. The machines affected seem to belong to corporate or government organizations.

 

gUtUe4r.jpg

 

The engineer in question, Tavis Ormandy, first made the vulnerability public back in May in a full-disclosure blog post. His actions have been criticized by industry members saying that the proper action would have been to report this privately to Microsoft so they can issue a fix before the vulnerability gets used “in the wild”. Google has distanced itself from Ormandy's actions, saying that his method of revealing the issue was a personal choice and did not represent the company. 

 

Now Microsoft is saying that they have seen “targeted attacks” using this particular bug, which could allow attackers to elevate their privileges on targeted machines. Microsoft has declined to comment on whether they think Ormandy’s actions have led to these attacks.

 

If you’re worried about attacks you should ensure that you have Automatic Updates turned on, as this vulnerability has now been patched via a Windows Update.

 

  • Like 1

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this  

×