tl;dr: a null deref in windows kernel when you connect to a malicious SMB share
Windows 10 0day exploit goes wild, and so do Microsoft marketers
11–20 of 78 posts
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#12He asked a PR person, probably one with little security background (how many security people do you know who went into PR?) gave the stock answer which does happen to actually be good security advice: run the latest supported version with patches. The reporter was just butthurt about not getting a scoop and decided to write an article complaining about PR practices in place of an actual story. Really like the click b…
>Windows is the only platform with a customer commitment to investigate reported security issues and proactively update impacted devices as soon as possible,
EDIT and this
>The time has come for Microsoft vulnerability disclosure communications to mute the marketers and let the security engineers do the talking instead.
I found it funny to be honest
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#13Does anybody know how many days it would take from when a critical security bug is discovered in Windows and assuming that the fix is just a few lines of code and not a component rewrite and marketing is not in the way, I am wondering how many steps are from when a fix is created until is released.(I imagine that there may some QA and some managers that need to approve it but I have no idea)
It depends. Some bugs can be fixed easily and some might be too complicate to fix even though it looks simple. Usually all critical bugs are attended as soon as they are created (few hours delay). But the actual fix depends on the bug and there is no general formula for that
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#14"I decided to release this bug one week before the patch is released, because it is not the first time Microsoft sits on my bugs. I'm doing free work here with them (I'm not paid in anyways for that) with the goal of helping their users. When they sit on a bug like this one, they're not helping their users but doing marketing damage control, and opportunistic patch release."
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#15The researcher disclosed the bug one week before Microsoft is scheduled to patch it. I'm sure MS isn't thrilled, but they did drag their feet: "I decided to release this bug one week before the patch is released, because it is not the first time Microsoft sits on my bugs. I'm doing free work here with them (I'm not paid in anyways for that) with the goal of helping their users. When they sit on a bug like this one, t…
If they weren't patching, I'd understand, but this isn't the right way to get attention in my book.
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#16Earlier quoted context omitted.
It depends. Some bugs can be fixed easily and some might be too complicate to fix even though it looks simple. Usually all critical bugs are attended as soon as they are created (few hours delay). But the actual fix depends on the bug and there is no general formula for that
>assuming that the fix is just a few lines of code
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#17The researcher disclosed the bug one week before Microsoft is scheduled to patch it. I'm sure MS isn't thrilled, but they did drag their feet: "I decided to release this bug one week before the patch is released, because it is not the first time Microsoft sits on my bugs. I'm doing free work here with them (I'm not paid in anyways for that) with the goal of helping their users. When they sit on a bug like this one, t…
The researcher sounds really petty. They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before. If they weren't patching, I'd understand, but this isn't the right way to get attention in my book.
It definitely puts pressure on MS but I don't think that's bad. Corporations have demonstrated time and again that the only way to get them to move is a PR hype.
If they want researchers to stop doing preliminary public disclosures, they should prioritize security higher than PR damage control.
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#18The researcher disclosed the bug one week before Microsoft is scheduled to patch it. I'm sure MS isn't thrilled, but they did drag their feet: "I decided to release this bug one week before the patch is released, because it is not the first time Microsoft sits on my bugs. I'm doing free work here with them (I'm not paid in anyways for that) with the goal of helping their users. When they sit on a bug like this one, t…
The researcher sounds really petty. They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before. If they weren't patching, I'd understand, but this isn't the right way to get attention in my book.
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#19Earlier quoted context omitted.
The researcher sounds really petty. They're patching it, but not on this person's schedule so he's causing microsoft and USERS problems they didn't have before. If they weren't patching, I'd understand, but this isn't the right way to get attention in my book.
There are very competent people on this planet who make a very good buck out of zero-days (not to mention remotely control users' machines, and steal data). IMO the researcher didn't want that particular vulnerability to dwell on somebody's todo list for several years. It definitely puts pressure on MS but I don't think that's bad. Corporations have demonstrated time and again that the only way to get them to move is…
Except the researcher themselves knew it was one more week, and not "several years." You cannot claim they were ignorant if their own statements shows that they were not.
Re: Windows 10 0day exploit goes wild, and so do Microsoft marketers
#20Earlier quoted context omitted.
There are very competent people on this planet who make a very good buck out of zero-days (not to mention remotely control users' machines, and steal data). IMO the researcher didn't want that particular vulnerability to dwell on somebody's todo list for several years. It definitely puts pressure on MS but I don't think that's bad. Corporations have demonstrated time and again that the only way to get them to move is…
> IMO the researcher didn't want that particular vulnerability to dwell on somebody's todo list for several years. Except the researcher themselves knew it was one more week, and not "several years." You cannot claim they were ignorant if their own statements shows that they were not.
I personally like Windows 10 a lot and I applaud any effort to turn it into a long-term stable OS.