New Windows 10 zero-day vulnerability surfaces online with proof of concept video

SHARE:

The researcher SandboxEscaper has again posted a zero-day vulnerability for the Windows operating system. The new flaw pertains to local pri...

The researcher SandboxEscaper has again posted a zero-day vulnerability for the Windows operating system. The new flaw pertains to local privilege escalation (LPE) and a proof of concept video has also been posted demonstrating how it works. While the exploit isn't of the sort that enables an attacker to gain access to your computer, it does demo how one could, at a later stage, gain administrator-level system privileges. If an intruder finds a way to get into your system, this LPE exploit can be used to gain access over the complete system. As the flaw is said to be a zero-day vulnerability, there’s a good chance threat actors are already in action to use it for nefarious purposes. 

Microsoft recently started rolling out Windows 10 May Update 1903 so it could take some time before a fix for the LPE is made available. A vulnerability analyst at CERT/CC, Will Dormann, confirmed that the flaw is working. He tweets, “I can confirm that this works as-is on a fully patched (May 2019) Windows 10 x86 system. A file that is formerly under full control by only SYSTEM and TrustedInstaller is now under full control by a limited Windows user. Works quickly, and 100% of the time in my testing." Dormann also confirms that the vulnerability works on 64-bit Windows 10 as well. SandboxEscaper also mentions that there are four more unpatched bugs that are yet to be disclosed, three LPEs and one sandbox escape. 

Also 64-bit Windows 10, if you're not afraid to compile your own code. pic.twitter.com/bcAxbZDDwp

— Will Dormann (@wdormann) May 21, 2019

It is unlikely that any real fix is available for the LPE until Microsoft issues a patch but as mentioned above, it can’t be used until someone gains access to your system. The best bet right now then seems to be protecting a system from external agencies. Users should avoid downloading malicious files and keep their system up to date. 

SandboxEscaper is infamous for releasing zero-day vulnerabilities. The researcher previously announced a flaw that’s capable of deleting system files and it was said to be affecting the Microsoft Data Sharing service (dssvc.dll) file, which is a local service for data exchange between applications. Exploiting the flaw, an attacker can gain admin permissions to compromise protected data on the computer. They can then delete system DLLs or replace them with malicious ones. 



from Latest Technology News http://bit.ly/2VKBGD0

COMMENTS

Name

7,1,Airtel,1,Andriod,1,Android,4,Android Q,1,apex,1,Apple,7,Apps,1,Asus Rog,1,Black Shark 2,2,Boeing 737 MAX,1,Bsnl,2,camera,2,CPU,3,Donald Trump,1,Earphone,1,Facebook,5,Fan,1,Fitbit,1,foldable Phone,2,Fortnite,1,Galaxy A40,1,Galaxy s10,1,Galaxy s10e,1,Games,10,gaming,1,Google,6,Google Pixel 2,1,Honor 10i,1,Huawe,1,Huawei,6,Huawei GT,1,IBM,1,Instagram,2,Internet,2,ios,2,iPad,2,iphone,2,Israel,1,jiomart,1,Laptop,1,Leica Q2,1,M20,1,mac,1,MacOS,1,Mi 9,1,Mi A2,1,Mi LED TV,1,MicroSoft,3,mobile,1,Moon,2,Mozilla,1,Nasa,2,News,1,Nokia,4,Nokia 62,1,Nvidias,1,OnePlus,4,Oppo,5,P30,3,Pixel,1,Poco F1,1,Pubg,12,Qualcomm,2,Redmi 3,1,Redmi 6 Pro,1,Redmi 7,1,Redmi Note 7,1,reliance,1,Reno,1,samsung,11,Skype,1,SmartPhone,56,Social,5,Spotify,1,Tech,35,Telecom,3,Touchpad,1,Tournament,1,TV,1,Twitter,1,Vivo,2,Watch,2,WhatsApp,1,Xbox,1,Xiaomi,16,y9li,1,
ltr
item
Genius Baba: New Windows 10 zero-day vulnerability surfaces online with proof of concept video
New Windows 10 zero-day vulnerability surfaces online with proof of concept video
http://feeds.feedburner.com/~r/digit/latest-news/~4/7P6MoY_Qh60
Genius Baba
https://geniusbabaa.blogspot.com/2019/05/new-windows-10-zero-day-vulnerability.html
https://geniusbabaa.blogspot.com/
https://geniusbabaa.blogspot.com/
https://geniusbabaa.blogspot.com/2019/05/new-windows-10-zero-day-vulnerability.html
true
7104319406113350277
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share. STEP 2: Click the link you shared to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy