Breaking News

PNY Unveils CS3250 M.2 NVMe PCIe Gen5 x4 SSD Arx 500 White ARGB – compact form and full performance from ENDORFY CORSAIR releases Top-of-class PCIe 5.0 SSD and Adds 4TB option in M.2 2242 size CASIO G-SHOCK Expands Its Premium Lineup with Two New Flagship Releases ADATA Launches World's First Two-in-one External SSD Integrated with Power Bank Module

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Google Discloses Unpatched Windows 7 Vulnerability

Google Discloses Unpatched Windows 7 Vulnerability

PC components Mar 8,2019 0

Google's Threat Analysis Group on February 27th, reported a 0-day vulnerability n Microsoft Windows 7 OS, which Microsoft has not yet corrected.

According to Google, "the vulnerability is a local privilege escalation in the Windows win32k.sys kernel driver that can be used as a security sandbox escape. The vulnerability is a NULL pointer dereference in win32k!MNGetpItemFromIndex when NtUserMNDragOver() system call is called under specific circumstances."

Google believes this vulnerability may only be exploitable on Windows 7 due to recent exploit mitigations added in newer versions of Windows. To date, Google's security researchers have only observed active exploitation against Windows 7 32-bit systems.

Google says it notified Microsoft about the issue, but since several days have passed and Microsoft says it is still "working on a fix," Google publicly disclosed it yesteday.

"..it is a serious vulnerability in Windows that we know was being actively exploited in targeted attacks. The unpatched Windows vulnerability can still be used to elevate privileges or combined with another browser vulnerability to evade security sandboxes, "Google said.

As mitigation advice for this vulnerability users should consider upgrading to Windows 10 if they are still running an older version of Windows, and to apply Windows patches from Microsoft when they become available.

The same vulnerability also affected Google Chrome, but Google says it released an update for all Chrome platforms on March 1.

Tags: bugsWindows 7Security
Previous Post
Businesses Continue to Pay Google in Order to Keep Their Brands Online
Next Post
Latest Windows 10 Update May Decrease PC Gaming Performance

Related Posts

  • HP Threat Research Shows Attackers Exploiting Zero‐Day Vulnerability Before Enterprises Can Patch

  • Samsung Develops New Security Chip For Mobile Devices

  • Samsung Says Your Galaxy S20’s Secure Processor Protects it Against Hardware Attacks

  • SK Telecom and Samsung Unveil the First QRNG-Powered 5G Smartphone

  • Microsoft Offers You $100,000 If You Can Hack the Linux-based Azure Sphere

  • Apple Says 'No Evidence' iPhone Mail Bug Used Against Consumers

  • Apple to Patch Serious iOS Vulnerability

  • AMD Downplays Reported Side Channel Vulnerabilities in Zen Chips

Latest News

PNY Unveils CS3250 M.2 NVMe PCIe Gen5 x4 SSD
PC components

PNY Unveils CS3250 M.2 NVMe PCIe Gen5 x4 SSD

Arx 500 White ARGB – compact form and full performance from ENDORFY
Cooling Systems

Arx 500 White ARGB – compact form and full performance from ENDORFY

CORSAIR releases Top-of-class PCIe 5.0 SSD and Adds 4TB option in M.2 2242 size
PC components

CORSAIR releases Top-of-class PCIe 5.0 SSD and Adds 4TB option in M.2 2242 size

 CASIO G-SHOCK Expands Its Premium Lineup with Two New Flagship Releases
Consumer Electronics

CASIO G-SHOCK Expands Its Premium Lineup with Two New Flagship Releases

ADATA Launches World's First Two-in-one External SSD Integrated with Power Bank Module
Consumer Electronics

ADATA Launches World's First Two-in-one External SSD Integrated with Power Bank Module

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

be quiet! Pure Base 501

be quiet! Pure Base 501

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed