Google Project Zero Immediately stop using Microsoft browsers

Google posted another unpatched Windows security flaw in accordance with Project Zero's program policy that reveals vulnerabilities 90 days after being notified to the developer.

This time, vulnerability is a type of confusion in a Microsoft Edge module and Internet Explorer. Google's researcher Ivan Fratric has published a PoC showing how browsers can drop, opening a door to potential intruders to acquire administrator privileges in affected systems.Project Zero

Discover more articles in search results.

Fratric reports that he analyzed the 64-bit version of Internet Explorer in Windows Server 2012 R2, but also two versions of 32-bits in Internet Explorer 11 and Microsoft Edge. This means that users of Windows 7, Windows 8.1, and Windows 10 are in imminent danger if they use Microsoft browsers.

Vulnerability was reported in 25 November, and according to Google Project Zero policy, it was announced publicly today 25 February, while Microsoft has not yet released a patch.

Let's say this is it second security flaw which was revealed by Google in two weeks, as the company also published details of the vulnerability in gdi32.dll originally reported to Microsoft in March of 2016.

So at this time there are two different security vulnerabilities that have not yet been repaired by Microsoft while the details have already been posted online on Google.

As mentioned in the article's title, to protect yourself, it is recommended that you avoid clicking on webpages that you do not trust but also replace Internet Explorer and Microsoft Edge with a different browser.

Google Project Zero PoC


Google preferences

Leave a Comment

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).