Google's Project Zero Reveals Zero-Day Exploit on Windows That Microsoft Hasn't Fixed Yet

Since Microsoft wasn't able to fix the bug in 90 days, Google's Project Zero team has now published the bug report.

Advertisement
By Jagmeet Singh | Updated: 14 June 2019 14:08 IST
Highlights
  • Project Zero researcher Tavis Ormandy has detailed the exploit on Twitter
  • The bug has been filed as "low severity"
  • Microsoft would bring the fix through the July Patch Tuesday release

The Project Zero team said that the bug exists in Windows' SymCrypt core cryptographic library

Google's Project Zero team has revealed a zero-day exploit affecting Windows systems. Microsoft was informed about the bug that is claimed to allow attackers to "take down an entire Windows fleet relatively easily", though the Redmond company hasn't been able to bring its fix in the 90-day window proposed originally. The issue is said to have its presence in Windows' SymCrypt core cryptographic library that is available for symmetric algorithms since Windows 8. The open-source project also debuted as the primary crypto library for asymmetric algorithms on the Windows 10 1703 build.

Project Zero researcher Tavis Ormandy through a series of tweets has detailed the exploit. "It's a DoS, but this means basically anything that does crypto in Windows can be deadlocked (s/mime, authenticode, ipsec, iis, everything). Microsoft committed to fixing it in 90 days, then didn't," Ormandy tweeted.

Advertisement

Since Microsoft wasn't able to fulfil its commitment on time, the Project Zero team has now published the bug report on the Chromium site. Ormandy has also created an X.509 certificate to trigger the bug that is believed to prompt a denial-of-service (DoS) attack on Windows servers. However, the bug has been marked with "low severity".

Senior Security Engineering Manager at Google Tim Willis in the Chromium post mentioned that Microsoft is still working on the fix. "MSRC [Microsoft Security Response Center] reached out to me and noted that the patch won't ship today and wouldn't be ready until the July release due to issues found in testing. As today is 91 days, derestricting the issue," said Willis.

Advertisement

It is likely that Microsoft would bring a fix through the next month's July Patch Tuesday release. Meanwhile, server admins should be aware of the vulnerability to avoid any inevitable incidents.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Claude Is Doubling the Usage Limits for the Next Two Weeks: Details
  2. OnePlus Nord 6 Series India Launch Teased as New Model Surfaces Online
  3. Samsung Galaxy A37, Galaxy A57 Spied in Leaked Hands-on Videos
  4. Motorola Razr 70 Listed on 3C Database Ahead of Anticipated Debut
  5. Huawei Teases an Imminent Return to India With the Launch of This Tablet
  1. Arc Raiders' AI Voice Lines Were Re-Recorded by Human Actors After Launch, Says Embark CEO
  2. Apple's iPhone 19e Said to Launch in 2028 With Upgraded LPTO OLED Display
  3. WLFI Governance Vote Passes Proposal Introducing Token Lock-Up Incentives
  4. Xiaomi Book Pro 14, Xiaomi Watch S5 China Launch Date Announced; Key Features Teased
  5. Realme C100 5G Listed on Retail Website With 6.8-Inch Display and 7,000mAh Battery
  6. Anthropic Doubles Claude’s Usage Limits for the Next Two Weeks: Details
  7. Australian Lawmakers Advance New Bill to Regulate Crypto Platforms
  8. Poco X8 Pro, Poco X8 Pro Max Camera Configuration and Display Features Revealed
  9. JBL Grip Portable Speaker With AI Sound Boost, Up to 12 Hours Battery Life Launched in India: Price, Features
  10. Samsung Begins Testing One UI 9 Beta for Galaxy S26 Ultra Ahead of Android 17 Release: Report
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.