• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / News / Windows: why we do not fix a few bugs directly

Windows: why we do not fix a few bugs directly

14/06/2018 07:47 by giorgos

Microsoft has released a draft document outlining which security vulnerabilities in Windows or other products will be updated immediately and which may be left for later.

The document outlines the criteria used by the Microsoft Troubleshooting Center to decide whether a reported vulnerability will be fixed immediately, usually in a security update for next Patch Tuesday, or released with another month's updates.windows bug - Windows: why not fix some bugs right away

Microsoft reports in a post on her blog that the document aims to provide researchers with "more clarity on security features, limits and fixes in Windows, and service commitments."

The criteria mentioned by the company for the assessment of the severity of the vulnerabilities can be summarized in two main questions:

1. Does the vulnerability break the promise of a security threshold or security feature that Microsoft is committed to defending? and
2. Does the severity of the vulnerability meet the company's line of service?

If the answer to both of the above questions is "yes", the error will be fixed in the next security update, but if the answer to both questions is "no", the vulnerability will be recorded for a subsequent update or a later version of the affected product , feature or service.

The promptness of the service used by the company seems to be determined by Microsoft's severity rating system, to help developers understand the risk of any vulnerabilities. So we have vulnerabilities that are critical, important, moderate, low and not at all.

"If a vulnerability is deemed critical or significant and concerns a security threshold or security feature that we have an obligation to service, then it will be addressed through a security update," the document said.

Microsoft lists below the eight types of security limits for which it has a service commitment. For example the company distinguishes vulnerabilities between kernel operation and user functions.

The security features that the company is committed to serving immediately are: BitLocker and Secure Boot, Windows Defender System Guard, Windows Defender Application Control, Windows Hello, Windows Resource Access Control, encryption platform, Host Guardian Service, and authentication protocols.

All registered security limits and security features supported by the company are included in the program Bug Bounty of Microsoft.

However, Microsoft service commitments do not apply to certain defense features, such as Control Flow Guard, Code Integrity Guard, and Arbitrary Code Guard. Other features excluded from service commitments include ransomware protection, and Microsoft antivirus, Windows Defender.

You can read the document for more information (PDF).

_______________________

  • Window 10 S Mode at the touch of a button in Settings
  • Window 10 Redstone 5 hit down the middle in third-party antivirus
  • Google Chrome removes the security indicator from HTTPS pages
Windows: why we do not fix a few bugs directly was last modified: 14 June, 2018, 7: 47 am by giorgos

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: Newstag: authentication, I'm sure, Microsoft, Patch Tuesday, ransomware, windows, Windows Defender, safety

You May Also Like

Microsoft Translator updated with 9 new languages
Microsoft Built
Inspire 2021: Microsoft announced the dates
What does Ctrl + Z do? More than you think

About Us giorgos

George still wonders what he's doing here ...

Previous Post: « MIT: Artificial Intelligence System monitors through walls
Next Post: SSD: How Do They Work? Advantages and disadvantages »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.