Now I understand. Google releases patches for its Chrome browser all the time. As @b explained about 36 hours ago, Google sent out a special alert to
[See the full post at: Google comes clean on that “emergency” security patch – and shows how it was used to trigger a Windows 7 0day]
![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Google comes clean on that “emergency” security patch – and shows how it was used to trigger a Windows 7 0day
Home » Forums » Newsletter and Homepage topics » Google comes clean on that “emergency” security patch – and shows how it was used to trigger a Windows 7 0day
- This topic has 11 replies, 6 voices, and was last updated 6 years, 2 months ago by
anonymous.
AuthorTopicwoody
ManagerMarch 8, 2019 at 7:03 am #338849Viewing 6 reply threadsAuthorReplies-
Microfix
AskWoody MVPMarch 8, 2019 at 7:29 am #338858How Microsoft will react is to include a fix in SMQR and SO patches and say nothing but document it a week later for respective patches. One thing for sure, it won’t be documented immediately upon patch release so a week is giving them the benefit of the doubt.
Opaque TransparencyWindows - commercial by definition and now function... -
anonymous
Guest -
brian1248
AskWoody LoungerMarch 8, 2019 at 8:54 am #338906A zero-day vulnerability is one for which there are active exploits even before it was announced. In other words, the “bad guys” knew about the bug and were actively exploiting it before the vulnerability was patched or even known about. Therefore, once it is discovered by the “good guys”, and before it can be patched, there are zero days before attacks using it will occur.
Many vulnerabilities (other than zero day vulnerabilities) have no active exploits and it could be many days or weeks before an exploit becomes available.
-
-
anonymous
Guest -
anonymous
GuestMarch 8, 2019 at 12:56 pm #339037This is great for others but what about persons stuck on Vista and using an “unsupported” chrome? There was a time where the security of the internet was critical on all being updated so the “virus” could not easily spread. Is that still true? Are these exploits done in old code or the current “patched” one? Is it even likely that a non patched computer or browser could be more secure then a patched one?
If the Above is true “There was a time where the security of the internet was critical on all being updated so the “virus” could not easily spread”, then would it not be in the interest of keeping ALL patched regardless of OS version or Browser Version? After all then a ‘unprotected’ browsers could in theory infect all others.
-
anonymous
GuestMarch 8, 2019 at 5:13 pm #339176You stick with old programs, your risk is increased but that doesn’t mean you will be hit. Generally, you (as in the person behind the keyboard) needs to do something that triggers the virus.
Very dated but possibly helpful article
Another possibly useful article
The problem with zero-day malware is your AV program will not ‘see’ it. Even VirusTotal is likely to report the file/link containing the malware is clean. So, occasionally run a demand scanner (examples: Malwarebytes; Superantispyware).
Something else that can function as a demand scanner on running processes is Sysinternals Process Explorer – look through the menu options options. Sysinternals Autoruns also has the VirusTotal option.
1 user thanked author for this post.
-
-
Nibbled To Death By Ducks
AskWoody PlusMarch 8, 2019 at 1:04 pm #339043“As mitigation advice for this vulnerability users should consider upgrading to Windows 10 if they are still running an older version of Windows, and to apply Windows patches from Microsoft when they become available. We will update this post when they are available.”
It makes one wonder, as I have through the decades, if MSFT was the source of some of these problems…great way to encourage “Updating your OS”!
“…when they become available”….what a laid back, ho-hum, indefensible attitude when a 0-day is in the wild!
Life sure looks different from underneath the bus…
Win7 Pro SP1 64-bit, Dell Latitude E6330 ("The Tank"), Intel CORE i5 "Ivy Bridge", 12GB RAM, Group "0Patch", Multiple Air-Gapped backup drives in different locations. Linux Mint Newbie
--
"The more kinks you put in the plumbing, the easier it is to stop up the pipes." -Scotty1 user thanked author for this post.
-
anonymous
GuestMarch 8, 2019 at 2:03 pm #339085Yep, the advisement to begin using Windows 10 as the mitigation looks evil and suggests collusion.
It also seems somebody at Microsoft quietly fixed that error not informing anybody else or there is actually a overall useful “tail covering” feature that mitigates the bug which still exists inside Windows 10.
-
-
EP
AskWoody_MVPMarch 8, 2019 at 5:33 pm #339189reaction from Born’s blog:
https://borncity.com/win/2019/03/08/kritische-chrome-schwachstelle-bedroht-32-bit-windows-7/
check out the last sentence on there that says “The recommendation of the Google developers to migrate to Windows 10 because of the bug seems to me as a bad joke.”
1 user thanked author for this post.
-
anonymous
Guest -
anonymous
GuestMarch 8, 2019 at 7:30 pm #339217Yes. I grudgingly admit Google is acting in good faith here. Because their product contributes to the exposure, they admit it openly and describe the broader problem as well. More information is better than less information. Of course it helps that they seem to have already patched their part.
Which actually means the opposite of your question. Chrome browser is now the one browser we know has been patched.
1 user thanked author for this post.
-
Viewing 6 reply threads - This topic has 11 replies, 6 voices, and was last updated 6 years, 2 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Android 15 and IPV6
by
Win7and10
1 hour, 12 minutes ago -
KB5058405 might fail to install with recovery error 0xc0000098 in ACPI.sys
by
Susan Bradley
7 hours, 22 minutes ago -
T-Mobile’s T-Life App has a “Screen Recording Tool” Turned on
by
Alex5723
10 hours, 4 minutes ago -
Windows 11 Insider Preview Build 26100.4202 (24H2) released to Release Preview
by
joep517
4 hours, 39 minutes ago -
Windows Update orchestration platform to update all software
by
Alex5723
17 hours, 24 minutes ago -
May preview updates
by
Susan Bradley
4 hours, 47 minutes ago -
Microsoft releases KB5061977 Windows 11 24H2, Server 2025 emergency out of band
by
Alex5723
6 hours, 58 minutes ago -
Just got this pop-up page while browsing
by
Alex5723
9 hours, 35 minutes ago -
KB5058379 / KB 5061768 Failures
by
crown
6 hours, 39 minutes ago -
Windows 10 23H2 Good to Update to ?
by
jkitc
3 hours, 49 minutes ago -
At last – installation of 24H2
by
Botswana12
1 day, 8 hours ago -
MS-DEFCON 4: As good as it gets
by
Susan Bradley
4 hours, 1 minute ago -
RyTuneX optimize Windows 10/11 tool
by
Alex5723
1 day, 21 hours ago -
Can I just update from Win11 22H2 to 23H2?
by
Dave Easley
1 day, 14 hours ago -
Limited account permission error related to Windows Update
by
gtd12345
2 days, 10 hours ago -
Another test post
by
gtd12345
2 days, 10 hours ago -
Connect to someone else computer
by
wadeer
2 days, 5 hours ago -
Limit on User names?
by
CWBillow
2 days, 8 hours ago -
Choose the right apps for traveling
by
Peter Deegan
1 day, 22 hours ago -
BitLocker rears its head
by
Susan Bradley
1 day, 6 hours ago -
Who are you? (2025 edition)
by
Will Fastie
1 day, 5 hours ago -
AskWoody at the computer museum, round two
by
Will Fastie
2 days ago -
A smarter, simpler Firefox address bar
by
Alex5723
2 days, 21 hours ago -
Woody
by
Scott
3 days, 6 hours ago -
24H2 has suppressed my favoured spider
by
Davidhs
1 day, 5 hours ago -
GeForce RTX 5060 in certain motherboards could experience blank screens
by
Alex5723
3 days, 20 hours ago -
MS Office 365 Home on MAC
by
MickIver
3 days, 14 hours ago -
Google’s Veo3 video generator. Before you ask: yes, everything is AI here
by
Alex5723
4 days, 10 hours ago -
Flash Drive Eject Error for Still In Use
by
J9438
1 day, 5 hours ago -
Windows 11 Insider Preview build 27863 released to Canary
by
joep517
5 days, 5 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.