Live data from Hacker News

Security Update for Microsoft Malware Protection Engine

technet.microsoft.com

1–10 of 85 posts

Re: Security Update for Microsoft Malware Protection Engine

#5
post #3

Serious props to Microsoft for getting the fix out the door so quickly. I'm glad that they took this seriously because this is a major vulnerability.

What is less impressive is that this exploit was even possible. Executing all incoming JavaScript as root user, what the heck?

Even if they patched this one bug in the interpreter, how many more are there that are not yet discovered / only known by dark market exploit vendors?

Re: Security Update for Microsoft Malware Protection Engine

#6
post #5
post #3

Serious props to Microsoft for getting the fix out the door so quickly. I'm glad that they took this seriously because this is a major vulnerability.

What is less impressive is that this exploit was even possible. Executing all incoming JavaScript as root user, what the heck? Even if they patched this one bug in the interpreter, how many more are there that are not yet discovered / only known by dark market exploit vendors?

Very true. I wouldn't be surprised if see more patches after this one. Based on their initial response time they seem to be taking this as seriously as it warrants. Hopefully they move away from this model eventually - it won't be easy to lock this down properly.

Re: Security Update for Microsoft Malware Protection Engine

#7
> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said.

This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how this could have 'helped the bad guys'.

Re: Security Update for Microsoft Malware Protection Engine

#9
post #7

> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…

They are commenting on the disclosure of the exploix and how to exploit it. Obviously everyone will have the patch installed.

Re: Security Update for Microsoft Malware Protection Engine

#10
post #7

> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…

Yeah, I don't get this. The announcement on twitter contained zero information apart from "there's a remote code exec vulnerability on windows". Which I think you could confidently say at ANY point in time (about ANY system).

But Graham and others (https://twitter.com/taviso/status/861575086632968192) continue to attack Tavis for announcing the fact that there is a known vulnerability. As if this somehow makes users more insecure.

Surely it is better to alert people (and especially organisations) that a major security issue has been found so that they can be prepared to patch their systems as soon as a fix is released?

Post reply on HN