Microsoft has issued a security patch that fixes the zero-day vulnerability tracked as CVE-2016-7255 exploited by Russian hackers. The vulnerability was exploited by attackers to gain administrator-level access by escaping sandbox protection and execute malicious code. Microsoft criticized the Google decision because the disclosure potentially puts customers at risk. Google has chosen to public disclose the flaw just 10 days after privately reporting it to Microsoft, giving the company a very little time to issue security updates. Microsoft has also issued security patches for 9 Flash Player flaws reported via ZDI.”]
Source: https://securityaffairs.co/wordpress/53242/hacking/cve-2016-7255-zero-day.html