Google has announced the existence of a zero-day vulnerability in Windows that is being actively exploited for attacks. According to researchers Neel Mehta and Billy Leonard of Google's security team, the Windows vulnerability with the identifier CVE-2016-7855 can be exploited to bypass the sandbox by exploiting a local privilege escalation bug in the Windows kernel .

The vulnerability according to the researchers can and is triggered “via system calls from win32k.sys to NtSetWindowLongPtr() for the GWLP_ID pointer to the GWL_STYLE window handle that is set to WS_CHILD.”
This particular vulnerability has already been disclosed to Microsoft and Adobe since October 21, and although Adobe was quick to patch the vulnerability by releasing an updated version of Flash Player – which is also affected – Microsoft seems not to have been quick enough.
In a security bulletin released, Adobe says it is aware of the vulnerability, which exists in the "wild" and is being used for limited, but targeted attacks against users running Windows 7, 8.1 and 10.
Google disclosed the security flaw (as it has been doing lately) before Microsoft had time to patch it, both because of its risk and because it was already being exploited by attackers.
Users are advised to immediately update Flash Player to the latest version and until a corresponding patch is released for Windows, they are urged to use Google Chrome in order to effectively protect themselves from potential attacks based on this vulnerability.
As experts explain, Chrome's sandbox blocks win32k.sys system calls using Windows 10's Win32k lockdown mitigation, which prevents the exploit of this particular 0-day.
https://security.googleblog.com/2016/10/disclosing-vulnerabilities-to-protect.html
