Slashdot Mirror


Google Security Expert Finds, Publicly Discloses Windows Kernel Bug

hypnosec writes "Security expert Tavis Ormandy has discovered a vulnerability in the Windows kernel which, when exploited, would allow an ordinary user to obtain administrative privileges of the system. Google's security pro posted the details of the vulnerability back in May through the Full Disclosure mailing list rather than reporting it to Microsoft first. He has now gone ahead and published a working exploit. This is not the first instance where Ormandy has opted for full disclosure without first informing the vendor of the affected software."

1 of 404 comments (clear)

  1. But not to give them a chance to correct it first? by Bruce66423 · · Score: 0, Flamebait

    That's bad. That's destructive and dangerous. He needs to be sacked for this, given the potential for this to be abused in the wild - otherwise we know that Google really is on the side of the criminals...