Oh, boy! Researchers found another unpatched Windows bug

By: Costea Lestoc
2 minute read
unpatched windows vulnerabilities

Security experts discovered a Windows vulnerability rated as a medium-severity. This allows remote attackers to execute arbitrary code and it exists within the handling of error objects in JScript. Microsoft didn’t roll out a patch for the bug yet. Trend Micro’s Zero Day Initiative Group revealed that the flaw was discovered by Dmitri Kaslov of Telespace Systems.

The vulnerability is not exploited in the wild

There’s no indication of the vulnerability being exploited in the wild, according to Brian Gorenc, ZDI’s director. He explained that the bug would only be part of a successful attack. He continued and said that the vulnerability allows code execution in a sandboxed environment and attackers would need more exploits to escape the sandbox and execute their code on a target system.

The flaw allows remote attackers to execute arbitrary code on Windows installations but user interaction is required, and this makes things less horrible. The victim would have to visit a malicious page or open a malicious file which would allow the execution of the malicious JScript on the system.

The glitch is in Microsoft’s ECMAScript standard

This is the JScript component that’s used in Internet Explorer. This causes problems because by performing actions in the script, attackers could trigger a pointer to be reused after it has been freed. The bug was first sent to Redmond back in January this year. Now. It’s being revealed to the public without a patch. The flaw is labeled with a CVSS score of 6.8, says ZDI and this means it flaunts a moderate severity.

According to Gorenc, a patch will be on its way as soon as possible, but no exact date has been revealed. So, we don’t know if it will get included in the next Patch Tuesday. The only available advice is for users to restrict their interactions with the application to trusted files.

RELATED STORIES TO CHECK OUT:

For various PC problems, we recommend this tool.

This software will repair common computer errors, protect you from file loss, malware, hardware failure and optimize your PC for maximum performance. Fix PC issues now in 3 easy steps:

  1. Download this PC Repair Tool rated "Excellent" on TrustPilot.com.
  2. Click “Start Scan” to find Windows issues that could be causing PC problems.
  3. Click “Repair All” to fix all issues with Patended Technologies (requires upgrade).

Discussions

Next up

Best Windows 10 antivirus software to use in 2018

By: Radu Tyrsina
7 minute read

Update – 2018 will soon come to an end and we already have a guide on what is the best antivirus you should get in […]

Continue Reading

These features are out for good with Windows 10 version 1809

iamsovy@gmail.com' By: Sovan Mandal
2 minute read

Microsoft is all set to launch its next big update, Windows 10 version 1809 in October. While that should be a nice piece of news […]

Continue Reading

Windows 10 18H2 builds no longer receive new features

By: Matthew Adams
3 minute read

The Windows 10 October 2018 Update (otherwise 18H2) rollout might now be two to three weeks away. For the last few months, new build previews […]

Continue Reading