news.mlab.sh
Back to the feed
vulnerability

Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

High
Summary

Microsoft has strongly criticized the public disclosure of zero-day vulnerabilities affecting Windows components, particularly following a researcher's independent disclosures. The company asserts that uncoordinated disclosures pose unnecessary risks to customers and actively work to mitigate these threats. This situation has led to the researcher's GitHub account being removed, escalating a conflict over vulnerability reporting processes.

The recent disclosure of multiple zero-day vulnerabilities, including BlueHammer, RedSun, UnDefend, YellowKey, GreenPlasma, and MiniPlasma, by researcher Chaotic Eclipse (Nightmare-Eclipse) has prompted a forceful response from Microsoft. The vulnerabilities, impacting components like Defender and BitLocker, were released publicly without prior notification to Microsoft, allowing for immediate exploitation. Microsoft emphasizes the potential 'real-world consequences' of such disclosures, highlighting the need for Coordinated Vulnerability Disclosure (CVD) to allow vendors time to develop and deploy security updates effectively.

The situation escalated when GitHub removed the researcher's account following the disclosures. The researcher expressed frustration with Microsoft's handling of the vulnerability reports, accusing the company of humiliation and a lack of recognition. Despite the removal of their account, the researcher subsequently uploaded the exploit code to GitLab. This incident underscores the complexities of vulnerability disclosure and the differing approaches between security researchers and technology vendors.

Read the full article at The Hacker News