News

Google Project Zero Finds “Crazy Bad” Windows Exploit

Google’s bug-hunting team has exposed a serious exploit in Windows 10. A member Project Zero, a group of security analysts that searches for zero-day vulnerabilities, disclosed its existence on Twitter on Monday (8th May). A Google researcher described the security flaw as “crazy bad” and “the worst Windows remote code exec in recent memory.”

“I think @natashenka and I just discovered the worst Windows remote code exec in recent memory. This is crazy bad. Report on the way,” tweeted Project Zero researcher. “Attack works against a default install, don’t need to be on the same LAN, and it’s wormable,” he added.

Project Zero has not publicly disclosed the nature of the vulnerability but has presumably notified Microsoft. Today’s monthly Windows Update may even include a patch for it.

Google Has a History of Exposing Windows Vulnerabilities

Google has made a habit of whistleblowing on Windows exploits. Earlier this year, Project Zero exposed a number of serious security issues with Windows 10: three within the space of a month. Project Zero gave Microsoft ample notice – 90 days, as per its policy – to fix the problems before the Google team went public.

Microsoft was none too happy with Google’s disclosure, explaining that public exposure of bugs is bad for users.

“We believe in coordinated vulnerability disclosure, and we’ve had an ongoing conversation with Google about extending their deadline since the disclosure could potentially put customers at risk,” a Microsoft spokesperson told Ars Technica. “Microsoft has a customer commitment to investigate reported security issues and proactively update impacted devices as soon as possible.”

Ashley Allen

Disqus Comments Loading...

Recent Posts

Electronic Arts Titles Played for Over 11 Billion Hours in 2024

Electronic Arts (EA) announced today that its games were played for over 11 billion hours…

6 days ago

Just 15% of Steam Gaming Time in 2024 Was Spent on New Releases

Steam's annual end-of-year recap, Steam Replay, provides fascinating insights into gamer habits by comparing individual…

6 days ago

STALKER 2 Gets Massive 110GB Patch With 1800+ Fixes

GSC GameWorld released a major title update for STALKER 2 this seeking, bringing the game…

7 days ago

Intel Unveils Core 200H Processors Based on the Previous Raptor Lake Refresh

Without any formal announcement, Intel appears to have revealed its new Core 200H series processors…

1 week ago

Ubisoft Reportedly Developing a New Quadruple A Game

Ubisoft is not having the best of times, but despite recent flops, the company still…

1 week ago

STALKER 2: Heart of Chornobyl Update 1.1 Fixes 1,800 Issues and Revamps A-Life 2.0

If you haven’t started playing STALKER 2: Heart of Chornobyl yet, now might be the…

1 week ago