{"id":1347,"date":"2016-12-02T12:30:31","date_gmt":"2016-12-02T12:30:31","guid":{"rendered":"https:\/\/antivirus.comodo.com\/blog\/?p=1347"},"modified":"2020-08-18T23:17:34","modified_gmt":"2020-08-18T17:47:34","slug":"google-discloses-critical-security-flaw-windows","status":"publish","type":"post","link":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/","title":{"rendered":"Google Discloses Critical Security Flaw in Windows"},"content":{"rendered":"<p>Google recently reported on a critical win32k.sys security flaw in Windows. This is a severe vulnerability as it allows cybercriminals to bypass typical security features of all versions of the Windows OS and infect the system with malware.<\/p>\n<p>This vulnerability is being actively exploited by a group called as STRONTIUM by Microsoft <a href=\"https:\/\/valkyrie.comodo.com\" target=\"_blank\" rel=\"noopener\">Threat Intelligence<\/a>. Microsoft claims that the attack is quite low in volume. STRONTIUM had initiated a spear-phishing campaign to target specific customers of Microsoft by exploiting two zero-day vulnerabilities in Adobe Flash and also the down-level Windows kernel. This malicious attack had been identified by Google\u2019s <a href=\"https:\/\/enterprise.comodo.com\/valkyrie\/\" target=\"_blank\" rel=\"noopener\">Threat Analysis<\/a> Group.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3110\" src=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/12\/Critical-Security-Flaw-in-Windows.jpg\" alt=\"windows security\" width=\"650\" height=\"300\" srcset=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/12\/Critical-Security-Flaw-in-Windows.jpg 650w, https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/12\/Critical-Security-Flaw-in-Windows-300x138.jpg 300w, https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/12\/Critical-Security-Flaw-in-Windows-225x104.jpg 225w\" sizes=\"auto, (max-width: 650px) 100vw, 650px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Windows Kernel Vulnerability<\/strong><\/p>\n<p>In technical parlance, the vulnerability can be considered to be a \u2018security hole\u2019 in the Windows kernel, which exists in all versions of the Windows OS till now (even Windows 10). According to Google the vulnerability \u201ccan be triggered via the win32k.sys system call NtSetWindowLongPtr() for the index GWLP_ID on a window handle with GWL_STYLE set to WS_CHILD.\u201d<br \/>\nThrough this &#8220;hole&#8221;, cyber criminals would gain elevated privileges for their malicious code that would help it escape a web browser&#8217;s sandbox, and then install the malware on the system. This would create a backdoor allowing access to the infected computer.<\/p>\n<p>Microsoft reports: &#8220;Customers using Microsoft Edge on Windows 10 Anniversary Update are known to be protected from versions of this attack observed in the wild.&#8221; It is also coordinating with Google and Adobe to develop patches to fix the issues.<\/p>\n<p>STRONTIUM leveraged a &#8220;use-after-free issue affecting ActionScript runtime code&#8221; vulnerability in Adobe Flash. Adobe has released a <a title=\"patch management\" href=\"https:\/\/www.itarian.com\/patch-management.php\" target=\"_blank\">patch update<\/a> to address this vulnerability.<\/p>\n<p>The STRONTIUM group suspected to be behind this attack usually targets high-value targets such as military organizations, defense contractors, <a href=\"https:\/\/www.comodo.com\/landing\/secure-government-institutions\/\" target=\"_blank\" rel=\"noopener\">government agencies<\/a>, large private sector organizations, and diplomatic institutions. They typically initiate their attack through spearphishing emails. They send emails from an already compromised victim&#8217;s computer to the target victim&#8217;s email id. They continue these attempts persistently for months together till they are able to infect the victim&#8217;s computer. From there on it spreads through the network and settles itself in very deep areas from where it can steal confidential, sensitive and valuable data.<\/p>\n<p><strong>Steps to protect the system from the win32k.sys vulnerability?<\/strong><\/p>\n<ul>\n<li>Update to the latest version of Flash.<\/li>\n<li>Upgrade to the latest version of Windows 10 OS. Microsoft recommends upgrading to Windows 10 and using Edge browser and Windows Defender<\/li>\n<li>Update Windows 10 OS to Windows 10 Anniversary edition<\/li>\n<li>Update the web browser \u2013 Edge, Chrome, etc..,<\/li>\n<li>Users of earlier Windows versions who do not yet want to upgrade to Windows 10 must utilize a robust <a href=\"https:\/\/antivirus.comodo.com\/antivirus-for-windows-10\/?track=8222\" target=\"_blank\" rel=\"noopener\">Antivirus for Windows10<\/a> and also keep it well updated.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/antivirus.comodo.com\/download\/thank-you.php?prod=cloud-antivirus&#038;track=16678&#038;af=16678\" target=\"_blank\" rel=\"noopener\" onclick=\"ga('send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Download', eventLabel: 'Bottom FREE DOWNLOAD banner Product AV'});ga('nT.send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Download', eventLabel: 'Bottom FREE DOWNLOAD banner Product AV'});\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-8604\" src=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2018\/04\/Comodo-Free-Antivirus.png\" alt=\"comodo antivirus\"\/><\/a><\/p>\n<p><a href=\"https:\/\/secure.nurd.com\/home\/purchase.php?pid=109&#038;af=16166\" target=\"_blank\" rel=\"noopener\" onclick=\"ga('send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Click', eventLabel: 'GET COMPLETE PROTECTION banner Product CIS Pro'});ga('nT.send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Click', eventLabel: 'GET COMPLETE PROTECTION banner Product CIS Pro'});\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8604\" src=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2020\/08\/complete-antivirus.png\" alt=\"comodo antivirus\" width=\"650\" height=\"83\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google recently reported on a critical win32k.sys security flaw in Windows. This is a severe vulnerability as it allows cybercriminals to bypass typical security features of all versions of the Windows OS and infect the system with malware. This vulnerability is being actively exploited by a group called as STRONTIUM by Microsoft Threat Intelligence. Microsoft [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":1478,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[40,56],"class_list":["post-1347","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-computer-safety","tag-antivirus-for-windows-10","tag-malware-protection"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Google Discloses Critical Security Flaw in Windows<\/title>\n<meta name=\"description\" content=\"Google\u2019s Threat Analysis Group identified win32k.sys vulnerability that allows cybercriminals cease security features of Windows OS and infects the system\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Google Discloses Critical Security Flaw in Windows\" \/>\n<meta property=\"og:description\" content=\"Google\u2019s Threat Analysis Group identified win32k.sys vulnerability that allows cybercriminals cease security features of Windows OS and infects the system\" \/>\n<meta property=\"og:url\" content=\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/\" \/>\n<meta property=\"og:site_name\" content=\"Comodo Antivirus Blogs | Anti-Virus Software Updates\" \/>\n<meta property=\"article:published_time\" content=\"2016-12-02T12:30:31+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-08-18T17:47:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/12\/RF-10296_thb_8.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"225\" \/>\n\t<meta property=\"og:image:height\" content=\"170\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"seo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"seo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/\",\"url\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/\",\"name\":\"Google Discloses Critical Security Flaw in Windows\",\"isPartOf\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/12\/RF-10296_thb_8.jpg\",\"datePublished\":\"2016-12-02T12:30:31+00:00\",\"dateModified\":\"2020-08-18T17:47:34+00:00\",\"author\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462\"},\"description\":\"Google\u2019s Threat Analysis Group identified win32k.sys vulnerability that allows cybercriminals cease security features of Windows OS and infects the system\",\"breadcrumb\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/#primaryimage\",\"url\":\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/12\/RF-10296_thb_8.jpg\",\"contentUrl\":\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/12\/RF-10296_thb_8.jpg\",\"width\":225,\"height\":170},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/antivirus.comodo.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Google Discloses Critical Security Flaw in Windows\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#website\",\"url\":\"https:\/\/antivirus.comodo.com\/blog\/\",\"name\":\"Comodo Antivirus Blogs | Anti-Virus Software Updates\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/antivirus.comodo.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462\",\"name\":\"seo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g\",\"caption\":\"seo\"},\"url\":\"https:\/\/antivirus.comodo.com\/blog\/author\/seo\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Google Discloses Critical Security Flaw in Windows","description":"Google\u2019s Threat Analysis Group identified win32k.sys vulnerability that allows cybercriminals cease security features of Windows OS and infects the system","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/","og_locale":"en_US","og_type":"article","og_title":"Google Discloses Critical Security Flaw in Windows","og_description":"Google\u2019s Threat Analysis Group identified win32k.sys vulnerability that allows cybercriminals cease security features of Windows OS and infects the system","og_url":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/","og_site_name":"Comodo Antivirus Blogs | Anti-Virus Software Updates","article_published_time":"2016-12-02T12:30:31+00:00","article_modified_time":"2020-08-18T17:47:34+00:00","og_image":[{"width":225,"height":170,"url":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/12\/RF-10296_thb_8.jpg","type":"image\/jpeg"}],"author":"seo","twitter_card":"summary_large_image","twitter_misc":{"Written by":"seo","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/","url":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/","name":"Google Discloses Critical Security Flaw in Windows","isPartOf":{"@id":"https:\/\/antivirus.comodo.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/#primaryimage"},"image":{"@id":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/#primaryimage"},"thumbnailUrl":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/12\/RF-10296_thb_8.jpg","datePublished":"2016-12-02T12:30:31+00:00","dateModified":"2020-08-18T17:47:34+00:00","author":{"@id":"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462"},"description":"Google\u2019s Threat Analysis Group identified win32k.sys vulnerability that allows cybercriminals cease security features of Windows OS and infects the system","breadcrumb":{"@id":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/#primaryimage","url":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/12\/RF-10296_thb_8.jpg","contentUrl":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/12\/RF-10296_thb_8.jpg","width":225,"height":170},{"@type":"BreadcrumbList","@id":"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/google-discloses-critical-security-flaw-windows\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/antivirus.comodo.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Google Discloses Critical Security Flaw in Windows"}]},{"@type":"WebSite","@id":"https:\/\/antivirus.comodo.com\/blog\/#website","url":"https:\/\/antivirus.comodo.com\/blog\/","name":"Comodo Antivirus Blogs | Anti-Virus Software Updates","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/antivirus.comodo.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462","name":"seo","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g","caption":"seo"},"url":"https:\/\/antivirus.comodo.com\/blog\/author\/seo\/"}]}},"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts\/1347","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/comments?post=1347"}],"version-history":[{"count":28,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts\/1347\/revisions"}],"predecessor-version":[{"id":15031,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts\/1347\/revisions\/15031"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/media\/1478"}],"wp:attachment":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/media?parent=1347"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/categories?post=1347"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/tags?post=1347"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}