Windows users appear to be exposed to attacks again, as a Google Project Zero developer has publicly disclosed an unpatched security flaw in Microsoft's operating system.
Google Project Zero team member Mateusz Jurczyk discovered a vulnerability in gdi32.dll that allows attackers to compromise Windows systems, and according to his blog, the flaw was first reported to Microsoft in March 2016.
Microsoft acknowledged the vulnerability and attempted to patch it with the MS16-074 update released in June 2016, but as Jurczyk reports, the company only managed to patch part of the problem.
Jurczyk reported the vulnerability to Microsoft again on November 16, 2016, but the company did not release a new patch. So, in accordance with Google Project Zero's vulnerability disclosure policy, the researcher disclosed the vulnerability publicly after 90 days.
This may sound a bit far-fetched, but it seems to be the best way to put pressure on every company to care more about end-user security.
Microsoft has yet to comment on this new revelation. It should be noted that the next scheduled update is scheduled for March 14th, and that this month's Patch Tuesday will not be released. This means that Windows users will remain vulnerable to attacks, at least until next month.
It should also be mentioned that if a malicious user wants to exploit this particular security flaw, they would have to create a special EMF file. It goes without saying that you should be careful with any file that comes from unknown sources.
This isn't the first time Google has published unpatched security vulnerabilities. The last time was in November 2016, which of course didn't sit well with Microsoft, which criticized Google for the disclosure, saying it puts all Windows users "at increased risk."
