Many of you have asked for my opinion about the “Google endangers us all as an act of hubris” articles making their way around the web. Emil Protalins
[See the full post at: Google discloses actively exploited Win vulnerability]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Google discloses actively exploited Win vulnerability
Home » Forums » Newsletter and Homepage topics » Google discloses actively exploited Win vulnerability
- This topic has 53 replies, 4 voices, and was last updated 8 years, 5 months ago by
Lily.
AuthorTopicViewing 52 reply threadsAuthorReplies-
b
Guest -
woody
Manager -
PKCano
Manager -
MikeFromMarkham
GuestNovember 2, 2016 at 8:27 am #24339If you’re using Windows 10 Anniversary Update and the Edge browser, than according to MS you’re “safe”.
Let’s do some quick ballpark estimates of the “safe universe” … they’re ballpark because my memory on where to find these references is fuzzy but I believe the numbers are close to reality:
– Recent reports put Windows 10 users at approximately 23% of the Windows universe
– Another recent report said AU installs are now at about 66% of all Windows 10 installs following a dramatic increase in the update roll-out
– Less than 25% of Windows 10 users currently use Edge as their primary browser
So combining these figures, less than 4% of all current windows users (.23 x .66 x .25 = 0.3795) are actually considered “safe” from this exploit.
If anyone has more accurate, up-to-date figures for this analysis, please correct my math.
Regardless, this is one security hole that needs to be patched and quickly, whether or not you care for how the parties involved handled the situation.
-
woody
Manager -
Annemarie
Guest -
Some Dude
Guest -
Terry Pickleson
Guest -
b
Guest -
MikeFromMarkham
Guest -
Ed
GuestNovember 2, 2016 at 9:51 am #24346Unless I misunderstood the wording in the article that’s posted below… if FLASH gets updated users are not at risk for this particular vulnerability. Is this correct?
“A source close to the company also shared that the exploit Google describes requires the Adobe Flash vulnerability. Since Flash has been patched, the Windows vulnerability is mitigated. That said, Microsoft still needs to plug the security hole as it could be leveraged in other types of attacks.”
-
woody
Manager -
woody
Manager -
woody
Manager -
PC Tech
Guest -
Not b
GuestNovember 2, 2016 at 10:11 am #24351Woodie-
From the “synopsis” link in your post:“Also on October 21, Google shared a Flash vulnerability (CVE-2016-7855) with Adobe, which that company patched on October 26. That means users can simply update to the latest version of Flash.”
“A source close to the company [i.e., Microsoft] also shared that the exploit Google describes requires the Adobe Flash vulnerability. Since Flash has been patched, the Windows vulnerability is mitigated.”
-
woody
Manager -
woody
ManagerNovember 2, 2016 at 10:15 am #24353I’m sure there will be exceptions but, yes, Microsoft’s behavior in recent months points to a push to have all security patches on Patch Tuesday.
But also note last month’s patches that weren’t released on Patch Tuesday – or documented in the main list of Win10 updates.
-
Jim4
GuestNovember 2, 2016 at 10:49 am #24354Microsoft was quoted as saying, “To address these types of sophisticated attacks, Microsoft recommends that all customers upgrade to Windows 10, the most secure operating system we’ve ever built, complete with advanced protection for consumers and enterprises at every layer of the security stack. Customers who have enabled Windows Defender Advanced Threat Protection (ATP) will detect STRONTIUM’s attempted attacks thanks to ATP’s generic behavior detection analytics and up-to-date threat intelligence.”
I suspect that at least part of the reason for all of the snooping going on by Microsoft is so that they can make Windows 10 more secure against this sort of attack. Likewise, that’s probably one of the reasons they are forcing all of the patches on just about everybody.
Just an observation; I’m neither agreeing nor disagreeing with what MS is doing.
-
woody
ManagerNovember 2, 2016 at 11:18 am #24355Yeah, but I’m skeptical.
As I understand it, Enterprises aren’t deploying it in droves because it requires the company to grant Microsoft access to users’ searches. And it only works on machines with Win10 1607 – the Anniversary Update.
There are deployment problems, as you would expect with any new security product
I’d be very interested in any info Microsoft is willing to share about the ways Win10 snooping enhance ATP! That’d be a very good use for the information collected.
-
T
GuestNovember 2, 2016 at 11:41 am #24356So those of us not using Windows 10 anniversary update, edge or chrome are screwed? I’m not convinced this is solely related to flash either, the wording seems to suggest both flash and a separate vulnerability. What’s the solution from both Google and Microsoft? Just use our browser for the former and make sure you upgrade to the latest OS for the latter, how convenient. I think they have a vested interest to get you using both those products. Say Microsoft patches this in next weeks updates, it’s gonna be lumped in with all the others, isn’t it? Either we install them immediately and hope nothing gets broken, otherwise the whole lot has to come out leaving you vulnerable yet again, or we wait for a few weeks as usual and remain vulnerable in the meantime. Thanks, Microsoft!
-
woody
ManagerNovember 2, 2016 at 11:59 am #24357It would appear – judging by published reports, repeated earlier in this thread – that updating to the latest version of Flash eliminates the problem.
I won’t swear to it, personally, but that’s the gist of one paragraph in one announcement.
Solution? Use Chrome. Google fixed it right away.
-
T
GuestNovember 2, 2016 at 12:19 pm #24358Yeah, maybe. I don’t use flash anyway, I managed to wean myself off that devil’s teat a while back. An abstinence based flash policy is the best policy. Using chrome is no solution for me though, I don’t even use google search and I block all their scripts (seriously, those scripts are EVERYWHERE). It terrifies me how much data they are hoovering up and it makes Microsoft look like amateurs.
-
Jim4
Guest -
Erik
GuestNovember 2, 2016 at 1:26 pm #24360Woody, this is interesting.
As an Enterprise, the Defense Department has bought into that Windows 10 is more secure and has directed the entire department to be on Windows 10 by Jan 2017 (in a letter dated the end of 2015).
I know that for the most part the Air Force hasn’t even started. They have just announced that they will finish transitioning to W10 by Jan 31st, 2018 (which the DoD states in their letter that you can have an automatic 12 month waiver)
Interesting that the Air Force is waiting until the last possible minute.
I wonder if they will have some sort of deal with Microsoft about the snooping… with all the PII (Personal Identifying Information) and privacy Act of 1974 stuff that will be on those systems in the NIPR Net.
Since the SIPR Net (Secure)won’t be connected to the regular internet, I wonder how the updating will go for that.
http://www.af.mil/News/ArticleDisplay/tabid/223/Article/921260/windows-10-to-deploy-across-af.aspx
I guess the DoD will trust Microsoft with everything that is on their systems. Sounds like it more of a ploy to reduce the number of Computer guys in the military base on what I read in those articles.
-
woody
Manager -
T
GuestNovember 2, 2016 at 2:26 pm #24362 -
Anonymous
Guest -
Anonymous
Guest -
Anonymous
Guest -
Anonymous
GuestNovember 2, 2016 at 4:38 pm #24366Safer perhaps… Any security guy worth their salt will never tell you, you’re safe. Only we’ve done what we can given our current knowledge and budget and what we’ve done today is subject to change tomorrow. One thing is sure, Microsoft may be plugging security holes in the house but with their telemetry you have given them permission to keep the front door wide open. Now you have to ask yourself if you trust Microsoft, I don’t, but even if they have the utmost integrity, they will eventually get hacked, they all do sooner or later, and they won’t mean to lose your data, but they will. On the other hand if they don’t have my data I won’t have to worry about it. Sticking with 7 until I can find a suitable replacement.
-
Anonymous
GuestNovember 2, 2016 at 5:05 pm #24367Flash Block? Why not just not install Flash?
Learn here ->->-> https://panopticlick.eff.org/about#methodology
Specifically scroll down to the bottom and look under the heading “Try to use a “non-rare” browser” to explain why using Flash Block is another plugin that will rarefy your browser and then test your browser here..
I bet you’ll find out your browsers “Fingerprint” is unique compared to Billions of other browsers.
-
Walker
GuestNovember 2, 2016 at 7:24 pm #24368Firefox updated the new Flash (23.0.0.205) on October 26, 2016.
FF always keeps it updated, however this add-on should always be checked often to ensure that it IS updated. Mine is also set to “Ask to Activate”.
I’ve always relied upon it to provide the latest update, and ensure that it is “enabled in protected mode”.
-
lizzytish
AskWoody LoungerNovember 2, 2016 at 7:57 pm #24369Fanboi….. Nosotros ????? Think perhaps you need to view ALL the comments on AskWoody to realise that the opinions are varied and sometimes include a certain ‘confrontation’ amongst the commentators here in their discussions…….. so that viewers/readers have a true input of things.
Regarding the subject of Flash, Woody is on record as saying that it’s not something you should have….. and there are many that still use it……. so the opinion is divided.
That’s not a v. nice remark and it is perhaps no wonder that you go by the name of Anonymous. LT
-
Mike in Texas
Guest -
woody
Manager -
lizzytish
AskWoody Lounger -
Eric
GuestNovember 3, 2016 at 10:34 am #24373 -
woody
ManagerNovember 3, 2016 at 10:47 am #24374Win10 Enterprise, properly configured, isn’t intrusive and all of the snooping it does gets sent back to the people paying the bill.
Advertising can also be turned off in the Enterprise (and Education) edition.
It’s us poor schnooks who can’t buy five copies at a time (and can’t afford to hire a full-time admin) who get privacy mugged.
-
Eric
Guest -
woody
Manager -
anonymous
GuestNovember 3, 2016 at 3:52 pm #24377Well now, that is a little bit unfair. I find this site to have no real fanboyism compared to many places on the net. It feels very inclusive for the most part as long as you don’t act like a d**k, whereas sevenforums can be very very sniffy to outsiders as woody will attest to. This is a nice place to be with very helpful contributors.
-
wdburt1
Guest -
anonymous
Guest -
Anonymous
GuestNovember 3, 2016 at 6:52 pm #24380Lizzytish, I was supporting T’s comment about the way Google hoovers up data, makes Microsoft look like amateurs and how he avoids them at all costs.
Regarding Adobe Flash, those in Comsec and hackers know how insecure it is… Fanbois talk about how installing the latest update “Will make you safe”. It’s dead and has been dead for a long time. It’s only still used to push obnoxious and virus ridden banner ads by website owners with financial incentive and by companies that offer services in exchange for track you, HTML5 has replaced it, is far more secure and is ubiquitous.
I post anonymously because I understand what you do not…
Respectfully,
-
woody
Manager -
woody
Manager -
lizzytish
AskWoody LoungerNovember 3, 2016 at 8:12 pm #24383@anonymous ..Well I am too always thankful for those who understand more than I do…… but I fail to see
your point of view of categorically saying you understand what I do not. How do you know that……. you have no idea of what I know and don’t know. I didn’t even comment about Flash.What one is objecting to is the word FANBOI..
it’s uncalled for. Simple as that.Most viewers who come here come from many different scenarios and those that comment offer their thoughts and ideas. Woody allows this diversity and it is because of this that AskWoody is a place for EVERYONE
regardless of what protocols they practice.If you feel in tune with certain ideas……… that’s great but don’t denigrate the rest of us…
that’s all! LT“Let us not look back in anger, nor forward in fear, but around in awareness.” – James Thurber
-
woody
Manager -
John W
GuestNovember 4, 2016 at 11:38 am #24385As Flash is on it’s way out to pasture to be replaced by HTML5, I say good riddance! It can’t happen soon enough!
The best way I have found to avoid Flash exploits is this:
Run Firefox as your main browser, but remove the Flash plugin from Firefox, and let sites like YouTube that can default to HTML5 do so.
Launch any pages or links that require Flash in Chrome. I let Chrome auto-update, so it always has the latest Flash plugin installed.
There is a convenient Firefox add-on that places a right-click context menu to open links in Chrome. It has a toolbar icon as well. https://addons.mozilla.org/en-US/firefox/addon/open-in-chrome/
-
Lily
GuestNovember 8, 2016 at 2:41 pm #24386Looks like the patch is out: https://www.catalog.update.microsoft.com/Search.aspx?q=KB3197868 – but which one should be used?
Thanks!
-
woody
Manager -
Lily
Guest
Viewing 52 reply threads - This topic has 53 replies, 4 voices, and was last updated 8 years, 5 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Key, Key, my kingdom for a Key!
by
RetiredGeek
1 hour, 6 minutes ago -
Registry Patches for Windows 10
by
Drcard:))
5 hours, 37 minutes ago -
Cannot get line length to NOT wrap in Outlining in Word 365
by
CWBillow
5 hours, 49 minutes ago -
DDU (Display Driver Uninstaller) updates
by
Alex5723
2 hours, 18 minutes ago -
Align objects on a OneNote page
by
CWBillow
11 hours, 5 minutes ago -
OneNote Send To button?
by
CWBillow
11 hours, 49 minutes ago -
WU help needed with “Some settings are managed by your organization”
by
Peobody
20 hours, 22 minutes ago -
No Newsletters since 27 January
by
rog7
16 hours, 18 minutes ago -
Linux Mint Debian Edition 7 gets OEM support, death of Ubuntu-based Mint ?
by
Alex5723
1 day ago -
Windows Update “Areca Technology Corporation – System – 6.20.0.41”
by
Bruce
1 hour, 26 minutes ago -
Google One Storage Questions
by
LHiggins
5 hours, 37 minutes ago -
Button Missing for Automatic Apps Updates
by
pmcjr6142
6 hours, 41 minutes ago -
Ancient SSD thinks it’s new
by
WSila
1 hour, 30 minutes ago -
Washington State lab testing provider exposed health data of 1.6 million people
by
Nibbled To Death By Ducks
1 day, 11 hours ago -
WinRE KB5057589 fake out
by
Susan Bradley
1 day, 4 hours ago -
The April 2025 Windows RE update might show as unsuccessful in Windows Update
by
Susan Bradley
19 hours, 8 minutes ago -
Firefox 137
by
Charlie
15 hours, 27 minutes ago -
Whisky, a popular Wine frontend for Mac gamers, is no more
by
Alex5723
1 day, 23 hours ago -
Windows 11 Insider Preview build 26120.3863 (24H2) released to BETA
by
joep517
1 day, 23 hours ago -
Windows 11 Insider Preview build 26200.5551 released to DEV
by
joep517
1 day, 23 hours ago -
New Windows 11 PC setup — can I start over in the middle to set up a local id?
by
ctRanger
19 hours, 37 minutes ago -
Windows 11 Insider Preview Build 26100.3902 (24H2) released to Release Preview
by
joep517
2 days, 3 hours ago -
Oracle kinda-sorta tells customers it was pwned
by
Nibbled To Death By Ducks
2 days, 9 hours ago -
Global data centers (AI) are driving a big increase in electricity demand
by
Kathy Stevens
2 days, 19 hours ago -
Office apps read-only for family members
by
b
2 days, 22 hours ago -
Defunct domain for Microsoft account
by
CWBillow
2 days, 19 hours ago -
24H2??
by
CWBillow
19 hours, 30 minutes ago -
W11 23H2 April Updates threw ‘class not registered’
by
WindowsPersister
15 hours, 24 minutes ago -
Master patch listing for April 8th, 2025
by
Susan Bradley
19 hours, 21 minutes ago -
TotalAV safety warning popup
by
Theodore Nicholson
1 day, 18 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.