Blog | G5 Cyber Security

Windows Zero-Day Drops on Twitter, Developer Promises 4 More

A Windows zero-day exploit dropped by developer SandboxEscaper would allow local privilege-escalation (LPE) by importing legacy tasks from other systems into the Task Scheduler utility. The bug in most ways is a typical LPE flaw, allowing a low-privileged user on the computer to arbitrarily modify any file, including system executables. Bugcrowd CTO and founder Casey Ellis told Threatpost that it could realistically be chained with comparatively more common and cheaper remote exploits. He said it works against a fully patched and up-to-date version of Windows 10, as well as Windows 8 and 2019.”]

Source: https://threatpost.com/windows-zero-day-lpe/144976/

Exit mobile version