Security Update for Microsoft Malware Protection Engine
technet.microsoft.com
Security Update for Microsoft Malware Protection Engine
1–10 of 85 posts
Re: Security Update for Microsoft Malware Protection Engine
#2Re: Security Update for Microsoft Malware Protection Engine
#3Re: Security Update for Microsoft Malware Protection Engine
#4https://technet.microsoft.com/en-us/library/security/4022344
Re: Security Update for Microsoft Malware Protection Engine
#5Serious props to Microsoft for getting the fix out the door so quickly. I'm glad that they took this seriously because this is a major vulnerability.
Even if they patched this one bug in the interpreter, how many more are there that are not yet discovered / only known by dark market exploit vendors?
Re: Security Update for Microsoft Malware Protection Engine
#6Serious props to Microsoft for getting the fix out the door so quickly. I'm glad that they took this seriously because this is a major vulnerability.
What is less impressive is that this exploit was even possible. Executing all incoming JavaScript as root user, what the heck? Even if they patched this one bug in the interpreter, how many more are there that are not yet discovered / only known by dark market exploit vendors?
Re: Security Update for Microsoft Malware Protection Engine
#7This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how this could have 'helped the bad guys'.
Re: Security Update for Microsoft Malware Protection Engine
#8Re: Security Update for Microsoft Malware Protection Engine
#9> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…
Re: Security Update for Microsoft Malware Protection Engine
#10> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…
But Graham and others (https://twitter.com/taviso/status/861575086632968192) continue to attack Tavis for announcing the fact that there is a known vulnerability. As if this somehow makes users more insecure.
Surely it is better to alert people (and especially organisations) that a major security issue has been found so that they can be prepared to patch their systems as soon as a fix is released?