Top Google engineer Tavis Ormandy has slammed Microsoft for apparently treating security bug hunters with “great hostility”.
He blasted Redmond's behaviour towards those who report vulnerabilities as he publicly revealed a new unpatched security hole in the Windows operating system - a bug that can be exploited to crash systems or gain administrator privileges. The vulnerable driver is present in "all currently supported versions" of Windows, according to the Googler
Ormandy discovered the flaw in the bezier curve-handling bit of the Win32k.sys kernel-level driver in March. However, triggering Microsoft's programming cock-up was difficult and at first the results were unpredictable.
|