Microsoft to fix actively exploited Windows flaw - next week
Microsoft said Tuesday that it will issue a fix next week for a Windows vulnerability it says is being exploited by hackers linked to Russia's government.
The company said in a blog post that it would release the fix November 8 as part of its normal patch cycle, adding that a well-known hacking group was already using the newly discovered flaw in a spearphishing campaign. The bug, which was publicly revealed by Google on Monday, can be used to bypass the security in the Windows32K system.
The revelation of the bug has caused some friction between Microsoft and Google. The search giant said it gave Microsoft 10 days to issue an advisory or a fix but that Microsoft failed to act. Google went public after that because it rated the bug as "critical" and learned it was being actively exploited. Microsoft disputed Google's assessment of the bug's threat and said Google's disclosure "could put customers at potential risk."