Google drops bombshell zero day exploit affecting Windows 10

Search for a command to run...

No comments yet. Be the first to comment.
FYI: This is experimental and may not work on your system.

Hey all! I made this guide after getting Starship successfully working on Bash, but zsh would refuse to accept the init script. Step 0 - Set a custom password This step is not required if you've already set a custom password for your Crostini contain...

If you've ever coded for an Arduino, you're probably familiar with the Arduino IDE. Is your IDE just not uploading your sketch? Are you getting an error such as this? If so, the fix is quite simple. First, locate the Tools section on the top bar of ...

Hey all! This is a quick one, but I use command aliases all the time and they make my life so much easier when I'm in the terminal. Let's get started! 1. Opening the .bashrc file The .bashrc file is short for "bash run commands". It can be located in...

GitHub CLI is a wonderful new tool released by GitHub in an effort to bring GitHub to the terminal. In this tutorial, I will be showing you how to setup, install and use some basic features of GitHub CLI. Installation Because of the amount of install...

Google has now publicly released details on a zero day exploit that hackers are supposedly actively using to hack Windows 10 and 7 PCs. Project Zero by Google gave Microsoft an ultimatum that the vulnerability needed to be fixed within 1 week. However, due to Microsoft’s lack of action, Google let the details on to the public scene.
This nameless exploit, labeled CVE-2020-17087, can be kryptonite to PCs running Windows 10 and 7 because it allows the attacker to elevate their user access level inside Windows.
Most cases of the exploit can be found used in connection with another bug in Google’s Chrome web browser which allowed the attackers to escape Chrome’s “sandbox” which could deploy and run malware on the host system. Fortunately, the bug involving Chrome has been fixed.
Ban Hawkes, the technical leader of Project Zero says that Microsoft plans to release a patch on the 10th of November. Microsoft themselves could not confirm this date but issued a statement saying in part: “Microsoft has a customer commitment to investigate reported security issues and update impacted devices to protect customers. While we work to meet all researchers’ deadlines for disclosures, including short-term deadlines like in this scenario, developing a security update is a balance between timeliness and quality, and our ultimate goal is to help ensure maximum customer protection with minimal customer disruption.”
However, the attacker’s motives are still unknown. Google’s threat intelligence director says the attacks were “targeted” but not related to the United States 2020 election.
The attacks were “very limited” according to a Microsoft spokesperson, and “no evidence to indicate widespread usage.” It’s yet another bug in the list of many to affect Windows this year. In January, the NSA helped find a “cryptographic bug”, but there was no evidence it was ever exploited.
Yet, in June and September, the U.S. Department of Homeland Security alerted to critical Windows bugs that included spread via internet and gaining elevated access to an entire Windows network.