Microsoft patches critical Windows drive-by bug

08.03.2011

In any case, Bryant added, there's no danger of any vulnerability exploited at Pwn2Own escaping into the wild. "Pwn2Own bugs are reported to vendors in a coordinated way," Bryant said.

HP TippingPoint, whose Zero Day Initiative (ZDI) bug bounty program sponsors Pwn2Own and pays out the vast majority of the cash prizes, buys the rights to the bugs exploited at the contest, then hands them over to the vendors. ZDI gives developers six months to patch any bug it buys before it publicly releases information.

Both Google and Mozilla have recently patched their browsers -- Google did again earlier today -- and before Pwn2Own begins.

Microsoft's security updates can be downloaded and installed via the Microsoft Update and Windows Update services, as well as through Windows Server Update Services (WSUS).

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at or subscribe to . His e-mail address is .