Get a Pentest and security assessment of your IT network.

News

Windows Zero-Day Drops on Twitter, Developer Promises 4 More

A Windows zero-day exploit dropped by developer SandboxEscaper would allow local privilege-escalation (LPE) by importing legacy tasks from other systems into the Task Scheduler utility. The bug in most ways is a typical LPE flaw, allowing a low-privileged user on the computer to arbitrarily modify any file, including system executables. Bugcrowd CTO and founder Casey Ellis told Threatpost that it could realistically be chained with comparatively more common and cheaper remote exploits. He said it works against a fully patched and up-to-date version of Windows 10, as well as Windows 8 and 2019.”]

Source: https://threatpost.com/windows-zero-day-lpe/144976/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2