Now I understand. Google releases patches for its Chrome browser all the time. As @b explained about 36 hours ago, Google sent out a special alert to
[See the full post at: Google comes clean on that “emergency” security patch – and shows how it was used to trigger a Windows 7 0day]
![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Google comes clean on that “emergency” security patch – and shows how it was used to trigger a Windows 7 0day
Home » Forums » Newsletter and Homepage topics » Google comes clean on that “emergency” security patch – and shows how it was used to trigger a Windows 7 0day
- This topic has 11 replies, 6 voices, and was last updated 6 years, 2 months ago by
anonymous.
AuthorTopicwoody
ManagerMarch 8, 2019 at 7:03 am #338849Viewing 6 reply threadsAuthorReplies-
Microfix
AskWoody MVPMarch 8, 2019 at 7:29 am #338858How Microsoft will react is to include a fix in SMQR and SO patches and say nothing but document it a week later for respective patches. One thing for sure, it won’t be documented immediately upon patch release so a week is giving them the benefit of the doubt.
Opaque TransparencyWindows - commercial by definition and now function... -
anonymous
Guest -
brian1248
AskWoody LoungerMarch 8, 2019 at 8:54 am #338906A zero-day vulnerability is one for which there are active exploits even before it was announced. In other words, the “bad guys” knew about the bug and were actively exploiting it before the vulnerability was patched or even known about. Therefore, once it is discovered by the “good guys”, and before it can be patched, there are zero days before attacks using it will occur.
Many vulnerabilities (other than zero day vulnerabilities) have no active exploits and it could be many days or weeks before an exploit becomes available.
-
-
anonymous
Guest -
anonymous
GuestMarch 8, 2019 at 12:56 pm #339037This is great for others but what about persons stuck on Vista and using an “unsupported” chrome? There was a time where the security of the internet was critical on all being updated so the “virus” could not easily spread. Is that still true? Are these exploits done in old code or the current “patched” one? Is it even likely that a non patched computer or browser could be more secure then a patched one?
If the Above is true “There was a time where the security of the internet was critical on all being updated so the “virus” could not easily spread”, then would it not be in the interest of keeping ALL patched regardless of OS version or Browser Version? After all then a ‘unprotected’ browsers could in theory infect all others.
-
anonymous
GuestMarch 8, 2019 at 5:13 pm #339176You stick with old programs, your risk is increased but that doesn’t mean you will be hit. Generally, you (as in the person behind the keyboard) needs to do something that triggers the virus.
Very dated but possibly helpful article
Another possibly useful article
The problem with zero-day malware is your AV program will not ‘see’ it. Even VirusTotal is likely to report the file/link containing the malware is clean. So, occasionally run a demand scanner (examples: Malwarebytes; Superantispyware).
Something else that can function as a demand scanner on running processes is Sysinternals Process Explorer – look through the menu options options. Sysinternals Autoruns also has the VirusTotal option.
1 user thanked author for this post.
-
-
Nibbled To Death By Ducks
AskWoody PlusMarch 8, 2019 at 1:04 pm #339043“As mitigation advice for this vulnerability users should consider upgrading to Windows 10 if they are still running an older version of Windows, and to apply Windows patches from Microsoft when they become available. We will update this post when they are available.”
It makes one wonder, as I have through the decades, if MSFT was the source of some of these problems…great way to encourage “Updating your OS”!
“…when they become available”….what a laid back, ho-hum, indefensible attitude when a 0-day is in the wild!
Life sure looks different from underneath the bus…
Win7 Pro SP1 64-bit, Dell Latitude E6330 ("The Tank"), Intel CORE i5 "Ivy Bridge", 12GB RAM, Group "0Patch", Multiple Air-Gapped backup drives in different locations. Linux Mint Newbie
--
"The more kinks you put in the plumbing, the easier it is to stop up the pipes." -Scotty1 user thanked author for this post.
-
anonymous
GuestMarch 8, 2019 at 2:03 pm #339085Yep, the advisement to begin using Windows 10 as the mitigation looks evil and suggests collusion.
It also seems somebody at Microsoft quietly fixed that error not informing anybody else or there is actually a overall useful “tail covering” feature that mitigates the bug which still exists inside Windows 10.
-
-
EP
AskWoody_MVPMarch 8, 2019 at 5:33 pm #339189reaction from Born’s blog:
https://borncity.com/win/2019/03/08/kritische-chrome-schwachstelle-bedroht-32-bit-windows-7/
check out the last sentence on there that says “The recommendation of the Google developers to migrate to Windows 10 because of the bug seems to me as a bad joke.”
1 user thanked author for this post.
-
anonymous
Guest -
anonymous
GuestMarch 8, 2019 at 7:30 pm #339217Yes. I grudgingly admit Google is acting in good faith here. Because their product contributes to the exposure, they admit it openly and describe the broader problem as well. More information is better than less information. Of course it helps that they seem to have already patched their part.
Which actually means the opposite of your question. Chrome browser is now the one browser we know has been patched.
1 user thanked author for this post.
-
Viewing 6 reply threads - This topic has 11 replies, 6 voices, and was last updated 6 years, 2 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Office gets current release
by
Susan Bradley
9 minutes ago -
FBI: Still Using One of These Old Routers? It’s Vulnerable to Hackers
by
Alex5723
10 hours, 5 minutes ago -
Windows AI Local Only no NPU required!
by
RetiredGeek
6 hours, 49 minutes ago -
Stop the OneDrive defaults
by
CWBillow
10 hours, 53 minutes ago -
Windows 11 Insider Preview build 27868 released to Canary
by
joep517
20 hours, 49 minutes ago -
X Suspends Encrypted DMs
by
Alex5723
23 hours, 1 minute ago -
WSJ : My Robot and Me AI generated movie
by
Alex5723
23 hours, 19 minutes ago -
Botnet hacks 9,000+ ASUS routers to add persistent SSH backdoor
by
Alex5723
23 hours, 56 minutes ago -
OpenAI model sabotages shutdown code
by
Cybertooth
1 day ago -
Backup and access old e-mails after company e-mail address is terminated
by
M W Leijendekker
12 hours, 43 minutes ago -
Enabling Secureboot
by
ITguy
19 hours, 43 minutes ago -
Windows hosting exposes additional bugs
by
Susan Bradley
1 day, 8 hours ago -
No more rounded corners??
by
CWBillow
1 day, 4 hours ago -
Android 15 and IPV6
by
Win7and10
18 hours, 1 minute ago -
KB5058405 might fail to install with recovery error 0xc0000098 in ACPI.sys
by
Susan Bradley
1 day, 20 hours ago -
T-Mobile’s T-Life App has a “Screen Recording Tool” Turned on
by
Alex5723
1 day, 23 hours ago -
Windows 11 Insider Preview Build 26100.4202 (24H2) released to Release Preview
by
joep517
1 day, 18 hours ago -
Windows Update orchestration platform to update all software
by
Alex5723
2 days, 6 hours ago -
May preview updates
by
Susan Bradley
1 day, 18 hours ago -
Microsoft releases KB5061977 Windows 11 24H2, Server 2025 emergency out of band
by
Alex5723
1 day, 9 hours ago -
Just got this pop-up page while browsing
by
Alex5723
1 day, 23 hours ago -
KB5058379 / KB 5061768 Failures
by
crown
1 day, 20 hours ago -
Windows 10 23H2 Good to Update to ?
by
jkitc
22 hours, 16 minutes ago -
At last – installation of 24H2
by
Botswana12
2 days, 22 hours ago -
MS-DEFCON 4: As good as it gets
by
Susan Bradley
6 minutes ago -
RyTuneX optimize Windows 10/11 tool
by
Alex5723
3 days, 10 hours ago -
Can I just update from Win11 22H2 to 23H2?
by
Dave Easley
1 day, 8 hours ago -
Limited account permission error related to Windows Update
by
gtd12345
3 days, 23 hours ago -
Another test post
by
gtd12345
4 days ago -
Connect to someone else computer
by
wadeer
1 hour, 25 minutes ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.