{"id":100201,"date":"2018-04-23T14:02:10","date_gmt":"2018-04-23T14:02:10","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=100201"},"modified":"2025-07-01T23:32:15","modified_gmt":"2025-07-02T06:32:15","slug":"google-has-found-a-security-flaw-in-microsofts-new-operating-system","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/google-has-found-a-security-flaw-in-microsofts-new-operating-system\/","title":{"rendered":"Google has found a security flaw in Microsoft\u2019s new operating system"},"content":{"rendered":"<p><a href=\"https:\/\/en.wikipedia.org\/wiki\/Zero-day_(computing)\">Zero-day vulnerabilities<\/a> are a type of computer program vulnerability unknown to the people who\u2019d most want to close that vulnerability. Remember back in November when somebody tweeted that <a href=\"https:\/\/en.softonic.com\/articles\/how-did-this-weeks-mac-vulnerability-affect-you\">anybody could log in to a MacBook running MacOS High Sierra<\/a> by merely typing root as the username? That was a zero-day vulnerability because it existed in the programming and Apple didn\u2019t know about it. These types of weakness are called zero-day because they day that the interested party (in the above example, Apple) learns about and closes the vulnerability is called Day Zero.<\/p>\n<p>Scary concept. There are software vulnerabilities out there that even the big players like Apple don\u2019t know about and they leave users wide open. To counter the scary threat posed by Zero-day vulnerabilities, back in July 2014, Google announced <a href=\"https:\/\/googleprojectzero.blogspot.com.es\/\" target=\"_blank\" rel=\"noopener noreferrer\">Project Zero<\/a>. Project Zero is a full-time team dedicated to finding zero-day vulnerabilities. One of the amazing things about Google\u2019s Project Zero is that it doesn\u2019t only search for vulnerabilities in Google software, it is looking out for all of us.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-88958 size-medium\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2016\/05\/what-google-knows-about-you-300x169.jpg\" alt=\"\" width=\"300\" height=\"169\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2016\/05\/what-google-knows-about-you-300x169.jpg 300w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2016\/05\/what-google-knows-about-you-768x433.jpg 768w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2016\/05\/what-google-knows-about-you-1024x576.jpg 1024w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2016\/05\/what-google-knows-about-you-800x450.jpg 800w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2016\/05\/what-google-knows-about-you-664x374.jpg 664w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2016\/05\/what-google-knows-about-you-238x134.jpg 238w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2016\/05\/what-google-knows-about-you-436x246.jpg 436w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2016\/05\/what-google-knows-about-you-370x208.jpg 370w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2016\/05\/what-google-knows-about-you-304x170.jpg 304w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2016\/05\/what-google-knows-about-you-1200x675.jpg 1200w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2016\/05\/what-google-knows-about-you.jpg 1280w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>Back in January Google\u2019s Project Zero discovered a vulnerability in Microsoft\u2019s newest desktop operating system Windows 10 S. In a <a href=\"https:\/\/bugs.chromium.org\/p\/project-zero\/issues\/detail?id=1514&amp;q=\" target=\"_blank\" rel=\"noopener noreferrer\">blog post<\/a>, Project Zero said that the vulnerability represents a medium security flaw:<\/p>\n<p><em>\u201cThis issue only affects systems with Device Guard enabled (such as Windows 10S) and only serves as a way of getting persistent code execution on such a machine. It&#8217;s not an issue which can be exploited remotely, nor is it a privilege escalation. An attacker would have to already have code running on the machine to install the registry entries necessary to exploit this issue, although this could be through an RCE such as a vulnerability in Edge. There&#8217;s at least two know DG bypasses in the .NET framework that are not fixed, and are still usable even on Windows 10S (e.g. https:\/\/tyranidslair.blogspot.co.uk\/2017\/08\/dg-on-windows-10-s-abusing-installutil.html) so this issue isn&#8217;t as serious as it might have been if all known avenues for bypass were fixed.\u201d<\/em><\/p>\n<div class=\"sc-card-starred-link\">\r\n  <div class=\"sc-card-starred-link__body\">\r\n    <div class=\"sc-card-starred-link__row clearfix\">\r\n      <div class=\"sc-card-starred-link__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-starred-link__img\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2017\/08\/updates-192.jpg\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-starred-link__col-title\">\r\n        <p class=\"sc-card-starred-link__title\">All the Best Free Software for your PC<\/p>\r\n        <a class=\"sc-card-starred-link__button\" href=\"https:\/\/en.softonic.com\/articles\/all-the-best-free-software-for-your-pc\" target=\"_blank\" rel=\"noopener noreferrer sponsored\">Click Here<\/a>\r\n      <\/div>\r\n    <\/div>\r\n    <a class=\"sc-card-starred-link__link\" href=\"https:\/\/en.softonic.com\/articles\/all-the-best-free-software-for-your-pc\" target=\"_blank\" rel=\"noopener noreferrer sponsored\"><\/a>\r\n  <\/div>\r\n<\/div>\n<p>The reason this is coming out now is that Project Zero has a 90-day action period. When it discovers a vulnerability, it notifies the interested party, but <strong>will then release news of the vulnerability publicly if an action hasn\u2019t been taken\u00a0<span style=\"background-color: #f5f6f5\">to close it\u00a0<\/span>in 90 days.<\/strong> Microsoft is not happy about Google\u2019s disclosure of the vulnerability as they told the search giant in February that they were working on the vulnerability but that it wouldn\u2019t be ready in time to meet Project Zero\u2019s 90-day deadline. This wasn\u2019t enough for Google, however, as Microsoft hasn&#8217;t given a solid release date for the next big Windows update.<\/p>\n<div class=\"sc-card-starred-link\">\r\n  <div class=\"sc-card-starred-link__body\">\r\n    <div class=\"sc-card-starred-link__row clearfix\">\r\n      <div class=\"sc-card-starred-link__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-starred-link__img\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/04\/woman-devices-sponsored-en-1024x576.jpg\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-starred-link__col-title\">\r\n        <p class=\"sc-card-starred-link__title\">What are VPNs and why should you use one<\/p>\r\n        <a class=\"sc-card-starred-link__button\" href=\"https:\/\/en.softonic.com\/articles\/what-are-vpns-and-why-should-you-use-on\/\" target=\"_blank\" rel=\"noopener noreferrer sponsored\">Find Out Now<\/a>\r\n      <\/div>\r\n    <\/div>\r\n    <a class=\"sc-card-starred-link__link\" href=\"https:\/\/en.softonic.com\/articles\/what-are-vpns-and-why-should-you-use-on\/\" target=\"_blank\" rel=\"noopener noreferrer sponsored\"><\/a>\r\n  <\/div>\r\n<\/div>\n<p>This isn\u2019t the first time that Google and Microsoft have squared off over the work of Project Zero. According to <a href=\"https:\/\/www.windowscentral.com\/google-discloses-medium-severity-security-flaw-windows-10-s\" target=\"_blank\" rel=\"noopener noreferrer\">Windows Central<\/a>, the same happened back in <a href=\"https:\/\/www.windowscentral.com\/microsoft-hits-back-google-publishing-windows-81-vulnerability\" target=\"_blank\" rel=\"noopener noreferrer\">2015<\/a> and <a href=\"https:\/\/www.windowscentral.com\/microsoft-butts-heads-google-over-critical-windows-vulnerability-disclosure\" target=\"_blank\" rel=\"noopener noreferrer\">2016<\/a> and most recently occurred\u00a0in <a href=\"https:\/\/www.windowscentral.com\/googles-project-zero-discloses-important-security-flaw-windows-10\" target=\"_blank\" rel=\"noopener noreferrer\">February<\/a> this year when Google released details of vulnerabilities in Windows 10 and Microsoft Edge.<\/p>\n<p>What are your thoughts on this issue? Is Project Zero providing a public service by rooting out unknown security issues and notifying the software developers or is it reckless to release details of such issues before they\u2019ve been dealt with? How does this compare to Microsoft\u2019s recent release <a href=\"https:\/\/en.softonic.com\/articles\/windows-defender-chrome-extension\" target=\"_blank\" rel=\"noopener noreferrer\">Windows Defender for Chrome<\/a>, a Chrome extension designed to close up security vulnerabilities in Google Chrome? Let us know in the comments below.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Zero-day vulnerabilities are a type of computer program vulnerability unknown to the people who\u2019d most want to close that vulnerability. Remember back in November when somebody tweeted that anybody could log in to a MacBook running MacOS High Sierra by merely typing root as the username? That was a zero-day vulnerability because it existed in &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/google-has-found-a-security-flaw-in-microsofts-new-operating-system\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Google has found a security flaw in Microsoft\u2019s new operating system&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9073,"featured_media":100207,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[],"tags":[2340],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-100201","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","tag-app-subdomain-redirectiongoogle"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/100201","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9073"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=100201"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/100201\/revisions"}],"predecessor-version":[{"id":328056,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/100201\/revisions\/328056"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/100207"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=100201"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=100201"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=100201"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=100201"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=100201"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=100201"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}