Google's Project Zero Reveals Zero-Day Exploit on Windows That Microsoft Hasn't Fixed Yet

Since Microsoft wasn't able to fix the bug in 90 days, Google's Project Zero team has now published the bug report.

Advertisement
By Jagmeet Singh | Updated: 14 June 2019 14:08 IST
Highlights
  • Project Zero researcher Tavis Ormandy has detailed the exploit on Twitter
  • The bug has been filed as "low severity"
  • Microsoft would bring the fix through the July Patch Tuesday release

The Project Zero team said that the bug exists in Windows' SymCrypt core cryptographic library

Google's Project Zero team has revealed a zero-day exploit affecting Windows systems. Microsoft was informed about the bug that is claimed to allow attackers to "take down an entire Windows fleet relatively easily", though the Redmond company hasn't been able to bring its fix in the 90-day window proposed originally. The issue is said to have its presence in Windows' SymCrypt core cryptographic library that is available for symmetric algorithms since Windows 8. The open-source project also debuted as the primary crypto library for asymmetric algorithms on the Windows 10 1703 build.

Project Zero researcher Tavis Ormandy through a series of tweets has detailed the exploit. "It's a DoS, but this means basically anything that does crypto in Windows can be deadlocked (s/mime, authenticode, ipsec, iis, everything). Microsoft committed to fixing it in 90 days, then didn't," Ormandy tweeted.

Since Microsoft wasn't able to fulfil its commitment on time, the Project Zero team has now published the bug report on the Chromium site. Ormandy has also created an X.509 certificate to trigger the bug that is believed to prompt a denial-of-service (DoS) attack on Windows servers. However, the bug has been marked with "low severity".

Advertisement

Senior Security Engineering Manager at Google Tim Willis in the Chromium post mentioned that Microsoft is still working on the fix. "MSRC [Microsoft Security Response Center] reached out to me and noted that the patch won't ship today and wouldn't be ready until the July release due to issues found in testing. As today is 91 days, derestricting the issue," said Willis.

Advertisement

It is likely that Microsoft would bring a fix through the next month's July Patch Tuesday release. Meanwhile, server admins should be aware of the vulnerability to avoid any inevitable incidents.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. iPhone 17 Price: US vs UAE vs India - Where Is It Cheapest to Buy?
  2. Nothing OS 4.0 With Android 16 Will Roll Out to Eligible Phones Soon
  3. Samsung Galaxy F17 5G With 5,000mAh Battery Launched in India
  4. Amazon's 10-Minute Delivery Service in Now Available in This City
  5. Arm's New C1 Processors Bring Big AI and Performance Gains
  6. You Can Now Sign Up to Test Xiaomi's HyperOS 3 Update
  7. Acer Nitro V15 (2025) Launched in India With This Nvidia RTX 50-Series GPU
  8. Realme P3 Lite 5G Price in India Revealed Ahead of Launch
  9. Xiaomi 16 Key Specifications Leaked, Might Debut With This Flagship Chip
  1. Oppo F31 Series Key Specifications Confirmed Ahead of September 15 India Launch
  2. Acer Nitro V15 (2025) Launched in India With Up To Nvidia GeForce RTX 5060 GPU: Price, Specifications
  3. Amazon Now Expands to Mumbai With 10-Minute Deliveries for Groceries, Essentials
  4. Arm C1 CPU Series Announced With Faster On-Device AI Performance and Better Efficiency for Smartphones
  5. PS Plus Game Catalog Adds WWE 2K25, Persona 5 Tactica, Green Hell and More in September
  6. Bitcoin Crosses $114,000 as US PPI Report Lifts Rate Cut Hopes
  7. Amazon Said to Be Developing AR Glasses With Camera, Display and Speakers
  8. YouTube Begins Global Rollout of Multi-Language Audio Dubbing Feature for Creators
  9. iPhone Air Design Vision Explained by Apple CEO Tim Cook, Other Executives
  10. Samsung Galaxy F17 5G Launched in India With 5,000mAh Battery, 50-Megapixel Rear Camera: Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.