Google Project Zero Team Discloses Windows 10 Flaw Before Microsoft Can Fix It

Advertisement
By Sumit Chakraborty | Updated: 21 April 2018 18:28 IST
Highlights
  • Google had reported the bug in January this year
  • Microsoft had asked for a deadline, which Google denied
  • The flaw affects Windows 10 machines with UMCI enabled

Google's Project Zero team has publicly disclosed a flaw in Windows 10, even though Microsoft wanted to keep it under wraps until it came up with a fix. The flaw affects Windows 10 S, which is a version of the operating system that the company had designed as a safer platform for educational institutions and other establishments by only allowing apps from the Microsoft Store to be installed. It also affects any Windows 10 system that has UMCI enabled. The move to disclose a flaw before a company is ready with a fix is not something unusual for the Google Project Zero team, which has shamed Microsoft with similar disclosures in the past.

According to the Project Zero team, the latest flaw targets any Windows 10 user with user mode code integrity (UMCI) enabled - commonly implemented in enterprise systems with Device Guard (DG) virtual container - which is a default setting in Windows 10 S. This issue enables arbitrary code to be run. Project Zero researcher James Forshaw has released a detailed description and proof-of-concept code for the bypass that allows attackers to gain persistent code execution on a PC or laptop. The bug is said to be within the .NET framework and how it works within the Windows Lockdown Policy (WLDP). It is also said to be amongst two other known and as yet unfixed Device Guard bypasses in the .NET framework.

Advertisement

Forshaw says, "It's not an issue which can be exploited remotely, nor is it a privilege escalation. An attacker would have to already have code running on the machine to install the registry entries necessary to exploit this issue, although this could be through an RCE such as a vulnerability in Edge." However, he adds, "There's at least two known DG bypasses in the .NET framework that are not fixed, and are still usable even on Windows 10 S so this issue isn't as serious as it might have been if all known avenues for bypass were fixed."

Google had first reported the bug to Microsoft on January 19 this year. In February, Microsoft confirmed it and said it could not be fixed by April's Patch deadline due to an "unforeseen code relationship". Again in April, the two companies haggled over disclosure dates. Microsoft had asked for an extension of two weeks on the 90-day disclosure deadline - something that the Google Project Zero denied. It again asked Google to hold off the disclosure of the bug until May's Patch that Google denied yet again.

Advertisement

From disclosing a Windows 10 Bug in 2016, to going public with a 'high severity' bug in Microsoft Edge and Internet Explorer last year, and more recently revealing an Edge Browser bug, engineers at the Google Project Zero have not shied away from publicly disclosing flaws in Microsoft products before the Redmond giant was able to fix them. To recall, the Google Project Zero team has a 90-day deadline for disclosing flaws from the date it informs the concerned company about the issue. It's no secret that the two companies have a not so pleasant history, as even Microsoft has had taken jabs at Google for its security vulnerabilities.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo Y6 5G Debuts With 7,200mAh Battery, 6.75-Inch Screen at This Price
  2. OTT Releases This Week: 24, Band Melam, Nukkad Naatak, Prathichaya, and More
  3. Leaked Dummy Gives Us an Early Look at the Design of the iPhone 18 Pro Max
  4. Instagram Launches Instants App With Disappearing Photos to Rival Snapchat
  5. Xbox Chief Asha Sharma Sets New Strategy, Says Will Reevaluate Exclusives
  6. Xiaomi Mix Fold 5 Might Be in Development With This In-House Chip
  7. Assassin's Creed Black Flag Resynced Revealed: Everything You Need to Know
  8. New Marketing-Focused Agentic AI Workflows Previewed at Adobe Summit 2026
  9. Redmi Note 17 Pro Max Leak Reveals Chipset, Camera Details
  10. Honor Earbuds 4 With Up to 46 Hours of Total Battery Life Debut Globally
  1. Jio Youth and Gaming Plan With Snapchat+, FanCode and Gemini Pro Launched: Price, Benefits
  2. Infinix GT 50 Pro Launched With Dimensity 8400 Ultimate, HydroFlow Liquid Cooling, Shoulder Triggers: Price, Features
  3. Adobe Previews New Agentic AI Workflows for Marketing Tasks at Adobe Summit 2026
  4. Microsoft Gaming Rebrands to Xbox, Debuts New Logo as Xbox Chief Says Company Reevaluating Exclusive Games
  5. Instagram Launches Instants App With Disappearing Photos to Rival Snapchat, BeReal
  6. Prathichaya (2026) Now Streaming Online: What You Need to Know
  7. Vivo X500 Series Tipped to Launch With 144Hz Displays, Ultrasonic Fingerprint Scanners
  8. Kelp Exploit Aftermath: DeFi Protocols Join Hands to Restore rsETH Following $293 Million Hack
  9. Microsoft Makes Copilot’s Agentic Features in Word, Excel and PowerPoint Generally Available
  10. OnePlus Ace 6 Ultra Battery Capacity Revealed as Company Teases ‘Energy Concentration’ Chip
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.