Search

Google's Project Zero Reveals Zero-Day Exploit on Windows That Microsoft Hasn't Fixed Yet

Since Microsoft wasn't able to fix the bug in 90 days, Google's Project Zero team has now published the bug report.

Advertisement
Highlights
  • Project Zero researcher Tavis Ormandy has detailed the exploit on Twitter
  • The bug has been filed as "low severity"
  • Microsoft would bring the fix through the July Patch Tuesday release
Google's Project Zero Reveals Zero-Day Exploit on Windows That Microsoft Hasn't Fixed Yet

The Project Zero team said that the bug exists in Windows' SymCrypt core cryptographic library

Google's Project Zero team has revealed a zero-day exploit affecting Windows systems. Microsoft was informed about the bug that is claimed to allow attackers to "take down an entire Windows fleet relatively easily", though the Redmond company hasn't been able to bring its fix in the 90-day window proposed originally. The issue is said to have its presence in Windows' SymCrypt core cryptographic library that is available for symmetric algorithms since Windows 8. The open-source project also debuted as the primary crypto library for asymmetric algorithms on the Windows 10 1703 build.

Project Zero researcher Tavis Ormandy through a series of tweets has detailed the exploit. "It's a DoS, but this means basically anything that does crypto in Windows can be deadlocked (s/mime, authenticode, ipsec, iis, everything). Microsoft committed to fixing it in 90 days, then didn't," Ormandy tweeted.

Since Microsoft wasn't able to fulfil its commitment on time, the Project Zero team has now published the bug report on the Chromium site. Ormandy has also created an X.509 certificate to trigger the bug that is believed to prompt a denial-of-service (DoS) attack on Windows servers. However, the bug has been marked with "low severity".

Senior Security Engineering Manager at Google Tim Willis in the Chromium post mentioned that Microsoft is still working on the fix. "MSRC [Microsoft Security Response Center] reached out to me and noted that the patch won't ship today and wouldn't be ready until the July release due to issues found in testing. As today is 91 days, derestricting the issue," said Willis.

It is likely that Microsoft would bring a fix through the next month's July Patch Tuesday release. Meanwhile, server admins should be aware of the vulnerability to avoid any inevitable incidents.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi 15 Ultra, Xiaomi 15 Now Available in India: See Price, Offers
  2. New CMF Phone Rear Camera Module Revealed in Teaser
  3. Vivo T4 5G India Launch Timeline, Design, Colourways, Key Features Leaked
  4. Kamel Guemra's Carjackers Now Streaming on Prime Video
  5. SpaceX's Fram2 Crew Captures First-Ever Views of Earth's Polar Regions
  1. NASA’s SPHEREx Mission Sends First Space Images Before Full Sky Survey
  2. Lava Breaches Grindavík's Defences as Volcanic Fissure Erupts in Iceland
  3. JWST Captures Unseen Details of Exoplanets in HR 8799 and 51 Eridani Systems
  4. SpaceX’s Fram2 Crew Captures First-Ever Views of Earth’s Polar Regions
  5. Massive X1.1-class Solar Flare Causes Radio Blackouts Across America
  6. SpaceX Fram2 Mission Lifts Off, First Private Flight Over Earth's Poles
  7. Laboratory Test Shows Ion-Molecule Collision Theory Fails to Produce Benzene in Space Conditions
  8. First Orbital Rocket Launch from Europe Fails as Spectrum Explodes Midair
  9. Choo Mantar Now Streaming on Prime Video After a Successful Theatrical Run
  10. Redline Now Available on Lionsgate Play: What You Need to Know About Action-Packed Racing Thriller
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »