Google Publicly Discloses Actively Exploited Windows Bug After Microsoft Misses Deadline

Google's Project Zero exposes a critical Windows vulnerability after giving Microsoft only a week to issue a patch. Attackers combine this flaw with a recently fixed Chrome bug to escape browser sandboxes and run malware.

Google publicly discloses details of a previously undisclosed Windows vulnerability, tracked as CVE-2020-17087, after Microsoft fails to meet a strict one-week patching deadline. Google’s elite Project Zero security team discovers that hackers actively exploit this bug to escalate their level of user access on Windows 7 and Windows 10 systems. The tech giant decides to release the technical information this afternoon despite the missing fix.

Attackers use this Windows flaw in conjunction with a separate Chrome bug that Google patches just last week. This combination allows malicious actors to escape Chrome’s secure sandbox environment and successfully run malware directly on the operating system. Microsoft plans to issue a patch for the Windows kernel bug on November 10, although the company does not independently confirm this specific date.

Google states that these ongoing attacks remain highly targeted and are not related to the upcoming U.S. election. A Microsoft spokesperson confirms that the observed attack is very limited in nature and shows no evidence of widespread usage. This discovery adds to a growing list of major Windows flaws this year that prompt urgent alerts from government cybersecurity agencies.

Read More at the original source →