News

Mysterious woman-hacker published exploit for increasing vulnerability of rights increase in Windows 10

On GitHub published PoC-code for vulnerability of privileges increase in Windows 10 that affects Windows Task Scheduler.

Despite vulnerabilities of rights’ shift do not allow hacking the system, attackers can use them on further stages to rise privileges from low level to level of administrator.

According to vulnerability description, published on GitHub, this bug is linked with the way Task Scheduler changes DACL extensions (Discretionary Access Control List, list of selective access management) for separate files.

Vulnerability allows attacker to rise rights on the system to administrator’s level and can be exploited with the use of specially formed .job file.

PoC–code published famous Internet-security expert SandboxEscaper. According to her words, exploit was tested on 32-bit Windows 10 systems, but, in theory, with certain adjustments can work on Windows XP and Server 2003 powered machines.

“That what starts with limited privileges ends up with SYSTEM rights when a particular function is encountered”, — said SandboxEscaper.

Old twitter post. Now SandboxEscaper microblog blocked.

Will Dormann, a vulnerability analyst at CERT/CC checked exploit’s code and confirmed that is works without changes in improved Windows 10×86 with 100% success. For working with 64-bit Windows 10 it is necessary to recompile a code.

“The exploit calls the code once, deletes the file, and then calls it again with an NTFS hard link pointing to the file that gets permissions clobbered with SetSecurityInfo()”, — Will Dormann told.

For Windows 7 and 8 exploit does not work.

SandboxEscaper wrote in her blog that she has four more undisclosed 0-day bugs for Windows, but she wants to sale them to “non-western” companies and interested partied for $60 000.

“I don’t owe society a single thing. Just want to get rich and give you *** in the west the middlefinger”, — said SandboxEscaper.

Source: https://www.bleepingcomputer.com

Polina Lisovskaya

I works as a marketing manager for years now and loves searching for interesting topics for you

Recent Posts

Remove Qehu Virus Ransomware (+File Recovery)

About Qehu Qehu is assorted by our virus analyst team as the DJVU cryptoware family.…

1 hour ago

Remove Qepi Virus Ransomware (+File Recovery)

About Qepi Qepi is assorted by our malware research team as the DJVU ransomware genus.…

1 hour ago

Remove Wifebaabuy.live Pop-up Ads

About Wifebaabuy.live Wifebaabuy.live pop-ups can not introduce out of the blue. If you have clicked…

4 hours ago

Remove Relativeads.net Pop-up Ads

About Relativeads.net Relativeads.net pop-ups can not open out of nowhere. If you have clicked on…

4 hours ago

Remove Vamtoacm.com Pop-up Ads

About Vamtoacm.com Vamtoacm.com pop-ups can not introduce out of the blue. If you have actually…

4 hours ago

Remove Clicks2apk.com Pop-up Ads

About Clicks2apk.com Clicks2apk.com pop-ups can not launch out of nowhere. If you have clicked on…

4 hours ago