OK I'll bite. What do you think the motive is?
According to the post's byline, it was written by Neel Mehta and Billy Leonard of the Threat Analysis Group at Google. Are you questioning their professional judgement and claiming they are individually biased?
If not, are you suggesting that there is some management directive to look for Windows exploits and publish them on an aggressive timeline in order to embarrass Microsoft publicly? Do you think professional security researchers would abide by such a directive?
There's no good reason for Google not to respect coordinated disclosure here. Making an arbitrarily tight deadline their policy isn't protecting users.
Now, tell me, how users would know about that without disclosing.
And, remember, there are already exploits
> The Windows vulnerability is a local privilege escalation in the Windows kernel that can be used as a security sandbox escape. It can be triggered via the win32k.sys system call NtSetWindowLongPtr() for the index GWLP_ID on a window handle with GWL_STYLE set to WS_CHILD.
Which is enough information for someone to write an exploit from scratch.
If they'd just said there is a win32k.sys vulnerability and advised users to make sure Flash is up to date, this would have been fine.
I'm starting to think the ultimate PC OS for IT would be one with a transactional audit trail on all changes to the PC.
1) try calling Google about a problem if you disagree with this statement
Also there's the consideration that security-critical environments who pay attention these have much more value-at-risk than the average Windows user. You want your safety critical systems who pay attention to be protected.
We don't yet know if this was being widely exploited (versus being a niche exploit used by an APT, for example), but it will be now either way.
https://security.googleblog.com/2013/05/disclosure-timeline-...
Stop spreading FUD without evidence.
n.b. https://adamcaudill.com/2015/11/19/responsible-disclosure-is...
There's no "right" answer because this is a holy war that's been going on for a very, very long time now.
Source: I've done these things before based off notices like this, and caught malware with it
I'd expect AV vendors to already have signatures for this given that it's being actively exploited, which means there must be malware samples to know this.
When there are known exploits attacks against users, giving a short time to get out quick patches to trusted software vendors makes a lot of sense, but I don't see a good reason for giving more than 24-48 hours before public disclosure.
In this case, the exploit was being actively used in the wild. That means bad actors already had access to this and it was the users who were in the dark. Now it may be added to the "toolkits" of scripters and people who buy exploit frameworks but the people who do real damage were already using it according to Google.
It's not just that people affected by this vulnerability are being protected by its disclosure (though there are reasons why that might be the case) it's that in the future vendors will take deadlines from P0 far more seriously when they realise that their reputation is on the line if they fail to patch in time.
If you let vendors get away with "we know that this is being actively exploited, but we haven't been able to come up with a timely fix, so please don't tell our customers how screwed they are", then that becomes the standard line and you need to keep letting deadlines slip. Or you don't let them slip and you end up with this sort of situation.
It goes both ways. As they said, this is active in the wild and many are being hacked AS WE SPEAK completely unaware of it. Imagine you had some information that is worth millions of dollars on your computer who is vulnerable to this. Now that you know, the first thing you'll do it turn off your computer or find a way to protect yourself. If they hadn't released it, you could've been hit in the coming week or month or however long it takes Microsoft.
As you can see, this isn't a black and white problem.
So if Google doesn't have any way to mitigate the vulnerability, all putting these details out do is allow more actors the chance to use the vulnerability until Microsoft can release a patch, which is exactly the opposite of responsible.