Microsoft scrambling to close gaping hole in Windows

Yesterday, we reported on a critical zero-day Windows vulnerability which is being actively exploited, and Microsoft has now given further details on this flaw (which was first revealed by Google) and assured users that it will be patched next week.

According to Terry Myerson, Executive VP, Windows and Devices Group at Microsoft, the company has coordinated efforts with Google and Adobe (there was also a Flash vulnerability highlighted) to concoct a patch for all versions of Windows.

This patch is now being tested, and will be rolled out next Tuesday, November 8.

As we noted yesterday, Microsoft wasn’t happy with Google’s public disclosure of the issue before a fix was implemented, and Myerson said: “Google’s decision to disclose these vulnerabilities before patches are broadly available and tested is disappointing, and puts customers at increased risk.”

Strontium dogs

Apparently the flaw has been actively used in a small-scale spear phishing campaign by a group called Strontium – more commonly known as ‘Fancy Bear’ these days, an organisation responsible for some high-profile hacks in the US targeting the likes of government agencies and other authorities.

Microsoft also took the time to clarify that those using the Edge browser with Windows 10 Anniversary Update are protected from the current strains of this attack spotted in the wild.

Yesterday, Google also noted that those running Chrome on Windows 10 were similarly protected.

The flaw itself was described by Google as a “local privilege escalation in the Windows kernel that can be used as a security sandbox escape”, meaning it allows an attacker to get around the system’s security sandbox in order to execute malicious code on the target machine.

Via: ZDNet

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That's Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog
The Meta Quest 3 and controllers on their charging station which is itself on a wooden desk next to a lamp
Forget Android XR, I've got my eyes on Vivo's new Meta Quest 3 competitor as it could be the most important VR headset of 2025
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS
Marvel Rivals
Marvel Rivals will get two new hero skins for Moon Knight and Black Panther this week meaning I'll now need to farm even more Units