<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Google Discloses 20-Year-Old Unpatched Flaw Affecting All Versions of Windows in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Google-Discloses-20-Year-Old-Unpatched-Flaw-Affecting-All/m-p/27368#M1732</link>
    <description>&lt;P&gt;FWIW, the article notes that Microsoft has patched it in this month's (August's?) patch set.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully we're good.&lt;/P&gt;</description>
    <pubDate>Wed, 28 Aug 2019 18:31:01 GMT</pubDate>
    <dc:creator>emb021</dc:creator>
    <dc:date>2019-08-28T18:31:01Z</dc:date>
    <item>
      <title>Google Discloses 20-Year-Old Unpatched Flaw Affecting All Versions of Windows</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Google-Discloses-20-Year-Old-Unpatched-Flaw-Affecting-All/m-p/26899#M1680</link>
      <description>&lt;P&gt;Anyone read this one yet and thought about the implications?&lt;/P&gt;&lt;P&gt;&lt;A href="https://thehackernews.com/2019/08/ctfmon-windows-vulnerabilities.html" target="_blank"&gt;https://thehackernews.com/2019/08/ctfmon-windows-vulnerabilities.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"A Google security researcher has just disclosed details of a 20-year-old unpatched high-severity vulnerability affecting all versions of Microsoft Windows, back from Windows XP to the latest Windows 10.&lt;/P&gt;&lt;P&gt;The vulnerability resides in the way MSCTF clients and server communicate with each other, allowing even a low privileged or a sandboxed application to read and write data to a higher privileged application.&lt;/P&gt;&lt;P&gt;MSCTF is a module in Text Services Framework (TSF) of the Windows operating system that manages things like input methods, keyboard layouts, text processing, and speech recognition."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This should keep many rather busy sorting this one out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:18:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Google-Discloses-20-Year-Old-Unpatched-Flaw-Affecting-All/m-p/26899#M1680</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-10-09T09:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: Google Discloses 20-Year-Old Unpatched Flaw Affecting All Versions of Windows</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Google-Discloses-20-Year-Old-Unpatched-Flaw-Affecting-All/m-p/26969#M1690</link>
      <description>Suppose 60% of vulnerabilities spend a fraction of their lifecycle as a zero day exploit. What are the odds we will start finding evidence of historical exploits for this vulnerability.</description>
      <pubDate>Fri, 16 Aug 2019 20:49:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Google-Discloses-20-Year-Old-Unpatched-Flaw-Affecting-All/m-p/26969#M1690</guid>
      <dc:creator>arctific</dc:creator>
      <dc:date>2019-08-16T20:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: Google Discloses 20-Year-Old Unpatched Flaw Affecting All Versions of Windows</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Google-Discloses-20-Year-Old-Unpatched-Flaw-Affecting-All/m-p/27368#M1732</link>
      <description>&lt;P&gt;FWIW, the article notes that Microsoft has patched it in this month's (August's?) patch set.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully we're good.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 18:31:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Google-Discloses-20-Year-Old-Unpatched-Flaw-Affecting-All/m-p/27368#M1732</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2019-08-28T18:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: Google Discloses 20-Year-Old Unpatched Flaw Affecting All Versions of Windows</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Google-Discloses-20-Year-Old-Unpatched-Flaw-Affecting-All/m-p/27577#M1769</link>
      <description>&lt;P&gt;I wonder how we could find evidence of usage of this kind of vulnerability, how many applications have stopped working the way they did since the update?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm minded of NSAKEY other built in doorways that are not even backdoors, known unknowns&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 23:23:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Google-Discloses-20-Year-Old-Unpatched-Flaw-Affecting-All/m-p/27577#M1769</guid>
      <dc:creator>Dave422537</dc:creator>
      <dc:date>2019-09-03T23:23:50Z</dc:date>
    </item>
  </channel>
</rss>

