Windows Zero-Day Vulnerability Comes With PoC on GitHub
Đăng ngày: 29 thg 8, 2018 · Tin tức · 1 phút đọc

A new zero-day vulnerability was recently made public following a Tweet from @SandboxEscaper, who claimed to be frustrated with Microsoft and, apparently, their bug submission process.
The tweet included a link to the proof-of-concept for the alleged zero-day vulnerability on GitHub, prompting security researchers to download and test @SandboxEscaper’s claims.
Following an assessment by CERT/CC vulnerability analyst Phil Dormann, the bug was verified and confirmed to be working on a fully-patched 64-bit Windows 10 machine, enabling attackers to gain admin privileges if exploited.
It’s unclear if the zero-day would work on all Microsoft supported Windows versions, including 32-bit ones, but it’s definitely cause for concern, since the PoC is publicly available and can easily be weaponized by threat actors.
While the zero-day does require some specific conditions for execution – an attacker needs the victim to download and execute a tainted application for the vulnerability to be exploited, an attack vector that is not uncommon, especially with APTs (Advanced Persistent Threats) and spearphishing.
“Microsoft Windows task scheduler contains a local privilege escalation vulnerability in the Advanced Local Procedure Call (ALPC) interface, which can allow a local user to obtain SYSTEM privileges,” reads the CERT/CC advisory. “The CERT/CC is currently unaware of a practical solution to this problem.”
While it’s uncertain whether Microsoft had been previously notified by @SandboxEscaper regarding the zero-day, the tweet does suggest that an interaction with Microsoft caused some friction.
Following the incident, a Microsoft spokesperson claims the company will “proactively update impacted devices as soon as possible,” potentially during a Patch Tuesday release.
Cr. Bitdefender
Bài viết liên quan

Bảo vệ gia đình bạn khỏi thủ đoạn lừa đảo AI "Tiếng khóc trẻ em" vô cùng tinh vi
Đăng ngày: 21 thg 7, 2026
Đọc bài viết
Data Breach (Rò rỉ dữ liệu) là gì? Và tại sao Bitdefender lại là giải pháp bảo mật tối ưu nhất?
Đăng ngày: 19 thg 7, 2026
Đọc bài viết
Cơn Sốt Bóng Đá: Đừng Để Kẻ Gian Ghi Bàn Vào Hệ Thống Bảo Mật Kỹ Thuật Số Của Bạn
Đăng ngày: 15 thg 6, 2026
Đọc bài viết
Người dùng Android cần xem ngay! 3 cách cài đặt khóa điện thoại chống ứng dụng ẩn danh hút sạch tiền tài khoản (Cập nhật mới nhất)
Đăng ngày: 12 thg 6, 2026
Đọc bài viết