Google publishes Windows security hole
Summary
In early 2015 Google published a hole in Windows 8.1 after Microsoft had not closed it within 90 days. Via NtApphelpCacheControl, a user with restricted rights could gain administrator rights. Google’s experts had found the vulnerability at the end of September 2014 and informed Microsoft.
Ideas
- A fixed deadline forces vendors to close holes in time.
- When it expires, the hole is published regardless of the patch status.
- The hole allowed local privilege escalation.
Insights
- Disclosure deadlines shift power from vendors to researchers and users.
- Rigid deadlines can also endanger users if the patch comes just afterwards.
Facts
- The hole concerned NtApphelpCacheControl in Windows 8.1.
- It was discovered at the end of September 2014.
- Google founded Project Zero in July 2014.
- At first Microsoft only responded with a comment, pointing out that a user account was required.
References
Critique
- The report does not discuss whether the rigid 90-day deadline endangered users in this case.
Remarks
- Google’s Project Zero still sticks to the 90-day deadline, supplemented by a short grace period.
Recommendations
- Plan patch processes so that updates are installed within a few days of publication.
- Follow publications by Project Zero and similar teams for the products you use.
Links to the original source and the Web Archive open in a new tab.