Windows 10 zero day was posted to GitHub

New Windows 10 zero day: A security researcher and exploit broker known as SandboxEscaper today released details of a zero day affecting Windows 10 and Windows operating systems 2019.

The details posted on GitHub, in the same repository, where the researcher has already published another eight zero days.

Today's exploit is a second bypass for Microsoft CVE-2019-0841 vulnerability. The first exploit for the same vulnerability was published two weeks ago.

Windows 10 zero day

According to Microsoft, CVE-2019-0841 is a vulnerability that allows users with very few rights to understand the owned by NT AUTHORITY\SYSTEM with a simple overwriting of the target file's permissions. 

Successful exploitation of course gives "full control" rights to the low that had minimal rights, according to Nabeel Ahmed of Dimension Data Belgium, who revealed the error to Microsoft.

Microsoft has released for the first time an update for CVE-2019-0841 April 2019.

In today, SandboxEscaper reports that there is a second way to bypass the fixes for CVE-2019-0841 and allow a low-privileged attacker to "play" with files over which he did not previously have full control.

Here we should mention that this is another one LPE (local privilege escalation) vulnerability, which means that attackers cannot exploit the flaw to break into systems, but can use it to gain full in files that would not normally be in control.

The zero day introduced today by SandboxEscaper uses an innovative technique, but there are certainly easier, faster and more efficient ways to get a higher permissions on Windows - for example, using one of SandboxEscaper's previous zero days.

It is also worth noting that although Microsoft had time to fix the previous three zero days, it did not fix them. To see if he does it in the next Patch Tuesday which is scheduled for next week, June 11th.

_________________

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).