Friday, January 14, 2011

Microsoft Patching: 0day still around and no forecasted release date

Microsoft Tuesday was a few days ago and no patch was released for the graphics rendering engine vulnerability. In a web conference, when asked when the patch was going to be released, Microsoft said they would not forecast a date. I understand this. I just wonder how mad they are with google researchers, when for the 2nd time(that I know) they release an exploit to force Microsoft to work hard for a fix.

MS is probably getting upset with these guys. Way I see it, its their fault. Take these guys more seriously.

Anyways, check out this site for a workaround:

I am working on putting out a video of how this could be exploited. Microsoft and IBM Xforce report that this is not being exploited in the wild.

