Jump to content
em

Windows 0 day priv escalation - fara sursa/nimic

Recommended Posts

Posted (edited)

A Google security engineer has not only discovered a Windows zero-day flaw, but has also stated that Microsoft has a knack of treating outside researchers with great hostility.

Tavis Ormandy, a Google security engineer, exposed the flaw on Full Disclosure, that could be used to crash PCs or gain additional access rights. The issue is less critical than other flaws as it's not a remotely exploitable one.

Ormandy said on Full Disclosure, "I don't have much free time to work on silly Microsoft code, so I'm looking for ideas on how to fix the final obstacle for exploitation.".

He's been working on it for months, and according to a later post, he has now a working exploit that "grants SYSTEM on all currently supported versions of Windows."

"I have a working exploit that grants SYSTEM on all currently supported versions of Windows. Code is available on request to students from reputable schools," Ormandy adds.

Sursa aici

Bucata de text intre ghilimele am gasit-o aici in comentarii

Banuiesc ca nu e fake dar nu avem sursa.

Further reading


http://seclists.org/fulldisclosure/2013/May/111

Si un cod demo care ar fi incomplet.

Edited by em

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...