• Archives
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Enterprise

Google Made A Windows Security Flaw Public And Microsoft Is Not Happy About It. Both Say They Are Right. See Details Here

Paul Balo by Paul Balo
November 1, 2016
in Enterprise, Security
Share on FacebookShare on Twitter

Google did something some think they could have handled in another way. They disclosed a critical security flaw in Windows in a public post yesterday even though they claim it that they first sent notice of this to Microsoft on the 21st of October. This bug allows attackers to escape from security sandboxes and they do this by exploiting a flaw in the win32K system.

“The Windows vulnerability is a local privilege escalation in the Windows kernel that can be used as a security sandbox escape. It can be triggered via the win32k.sys system call NtSetWindowLongPtr() for the index GWLP_ID on a window handle with GWL_STYLE set to WS_CHILD. Chrome’s sandbox blocks win32k.sys system calls using the Win32k lockdown mitigation on Windows 10, which prevents exploitation of this sandbox escape vulnerability.”

Well Google says it came out publicly just 10 days after reporting it to Microsoft to protect users or make them aware of this while Microsoft develops a patch for the flaw. They want users to have enough information about this because exploiting this bug in the win32K system also depends on a hacker breaking separately into Adobe Flash. A patch has been issued for this and Google is urging users to update the software. We encourage users to verify that auto-updaters have already updated Flash — and to manually update if not — and to apply Windows patches from Microsoft when they become available for the Windows vulnerability.

But why did they make it public if Microsoft is already working on a patch?

The first thing to know is that Microsoft is not happy with the disclosure because hackers who may not have known of that flaw could suddenly start exploiting this. In a statement provided by Microsoft on VentureBeat, they said the following;

“We believe in coordinated vulnerability disclosure, and today’s disclosure by Google puts customers at potential risk…Windows is the only platform with a customer commitment to investigate reported security issues and proactively update impacted devices as soon as possible. We recommend customers use Windows 10 and the Microsoft Edge browser for the best protection.”

But Google has a defense;

In 2013, they updated their policy with respect to making vulnerabilities public.  Let me quote a portion of the policy below for you to see;

Based on our experience, however, we believe that more urgent action — within 7 days — is appropriate for critical vulnerabilities under active exploitation. The reason for this special designation is that each day an actively exploited vulnerability remains undisclosed to the public and unpatched, more computers will be compromised.

Seven days is an aggressive timeline and may be too short for some vendors to update their products, but it should be enough time to publish advice about possible mitigations, such as temporarily disabling a service, restricting access, or contacting the vendor for more information.

So if you want to interpret the above quote literally, it means they don’t think Microsoft’s anger over this is justified. But if you also consider that this is the first time they would be invoking that policy in three years, then you may also think something doesn’t sound right about this. Microsoft’s is major tech rival to Google and this could be interpreted as a business decision.

In any case, update Flash on your Windows computer while Microsoft works to deal with the flaw in its win32K system.

Related Posts:

  • microsofts-surface-duo-dualscreen-androi-5f1f3d057e8c350ae07dd862-1-jul-28-2020-15-24-20-poster
    Microsoft Patch Tuesday Fixes 63 Bugs, 1 Zero-Day
  • 020tYFWBL4Yz8jIIFUdKDR1-22
    A Fix to Microsoft Windows Defender And Security Flaws
  • 11-1024×576
    Count Down To The End Of Windows 10 Microsoft Support
  • Windows_11
    Microsoft Fixes Windows Certificate Enrolment Bug
  • microsoft-365-app-icon-1
    M365 Apps on Windows 10 to Receive Security Updates…
  • STK_109_WINDOWS_C_84940e2be8
    KB5070311 Update Causes Dark Mode Flash Issue,…
  • maxresdefault (1)
    How to Upgrade to Windows 11 for Free As Windows 10…
  • windows-update-close
    Microsoft Releases Emergency Patch For Windows Update Bug

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: cyber securitygooglehackersmicrosoftsecuritywin32kwindows
Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Cursor Introduces An AI Coding Tool For Designers December 12, 2025
  • OpenAI Unveils More Advanced Model as Google Rivalry Grows December 12, 2025
  • WhatsApp Is Redefining The Voicemail Features For Users December 12, 2025
  • Microsoft’s Nadella Is Building a Cricket App in His Spare Time December 12, 2025
  • Google Photos Expands ‘Remix’ Feature to More Countries December 12, 2025
  • Google Play Store Reinstates Fortnite December 12, 2025
  • Vodacom Announces Price Hike December 12, 2025
  • ChatGPT Set to Launch ‘Adult Mode’ By Q1 2026 December 12, 2025
  • Amazon to Invest $35B in India by 2030 for Jobs & AI Growth December 11, 2025
  • SpaceX May Launch Its Big IPO Next Year With a $1tr Valuation December 11, 2025
  • GPT-5.2 Debuts as OpenAI Answers “Code Red” Challenge December 11, 2025
  • Netflix Plans Heavy Borrowing to Fund Warner Bros Deal December 11, 2025

Browse Archives

December 2025
MTWTFSS
1234567
891011121314
15161718192021
22232425262728
293031 
« Nov    

Quick Links

  • About TechBooky
  • Advertise Here
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • About TechBooky
  • Advertise Here
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.