Following a messed-up Microsoft January update, the Windows 10 bug affects all unpatched Windows 10 versions. It’s a bug for which a proof-of-concept exploit is currently publicly available, leaving exploitation in the hands of cybercriminals of all ranks.
Gil Dabah, the founder and CEO of Privacy Piiano, tweeted that he decided not to disclose the bug two years ago because he was having trouble being funded on some other bug bounties via the Microsoft program.
According to Microsoft, sophisticated parties exploited the vulnerability as a zero-day issue.
Windows server update troubles plagued January’s Patch Tuesday, which may have caused internal security teams to hesitate before installing the upgrades.
A way to eliminate the bug class is to improve the zero-day kernel bounty, start letting security experts join the bounty program, and assist the system to become more perfect.
It’s worth noting that Microsoft seems to have been inclined to dedicate more money into bug-bounty programs for other high-profile programs, such as the declaration of last spring that the corporation would pay up to $30,000 for Teams bugs.
#Vulnerability # Windows10 #Cybersecurity #News

Share: