NewsSoftware

Google Project Zero detects a vulnerability in Windows 10 S

New security problem, in this case related to Windows 10 S, which has been discovered by Google Project Zero, the same ones that Specter and Meltdown discovered.

In addition to being the most popular search engine, Google also has many divisions, such as the division that is responsible for searching for vulnerabilities, called Google Project Zero. This division was made known to the general public after the Meltdown and Specter vulnerabilities that affect processors from Intel, AMD and ARM became known. Now they have detected a new security problem, this one of medium degree, within Microsoft's Windows 10 S, which is integrated in the user mode code (UMCI) enabled.

Windows 10 S is an operating system especially focused on security, which implements a large number of restrictions, including the inability to run Win32 applications. Project Zero has found a bug, which allows the execution of an arbitrary code in a system with UMCI enabled, such as Device Guard, which is enabled by default in Windows 10 S. It only affects those who have Device Guard. enabled and cannot be remotely exploited, so the potential impact is reduced.

Google notified Microsoft of this problem on January 19, but the company that developed the operating system has not yet implemented a patch before the April update. Microsoft asked Google for a period of 14 days, informing that they would solve it in May. The term exceeds the grace date given by Google and the request for more time has been rejected.

Microsoft exposed this request to Google last week to extend the deadline to make the information public, claiming that it would be solved with the Redstone 4 update, something rejected by Google, claiming that Redstone 4 did not have a firm date and that this update did not I would implement a widely available patch.

It is not a written standard, but normally security companies usually give 90 days for these security problems to be solved, to prevent attackers from taking advantage of vulnerabilities. Google's 90-day grace period ended yesterday, so the information has been released. This will force Microsoft to release a hotfix before the planned update.

Source: neowin

Show more

Robert Sole

Director of Contents and Writing of this same website, technician in renewable energy generation systems and low voltage electrical technician. I work in front of a PC, in my free time I am in front of a PC and when I leave the house I am glued to the screen of my smartphone. Every morning when I wake up I walk across the Stargate to make some coffee and start watching YouTube videos. I once saw a dragon ... or was it a Dragonite?

Related publications

Leave your comment

Your email address will not be published. Required fields are marked with *

Button back to top
CLOSE

Ad blocker detected

This site is funded through the use of advertising. We always make sure that the advertising is not too intrusive for the reader and we prioritize the reader's experience on the website. However, if you block the ads, part of our funding will be reduced.