Thursday, October 25, 2018

SandboxEscaper, a researcher who back in August tweeted out a Windows privilege escalation bug, has published another unpatched Windows flaw on Twitter.

The new bug has some similarities to the previous bug. Windows services usually run with elevated privileges. Sometimes they perform actions on behalf of a user, and to do this they use a feature called impersonation. These services act as if they were using a particular user's set of privileges. After they've finished that action, they revert to their normal, privileged identity.

Both this bug and SandboxEscaper's previous bug depend on improper use of impersonation—specifically, the services in question (last time it was Task Scheduler, this time it's the "Data Sharing Service") revert their impersonation too quickly and end up performing some actions with elevated privileges when they should in fact have been impersonated. The last bug allowed one file to be written over another. In this case, it's a call to delete a file that is improperly impersonated, ultimately giving regular unprivileged users the ability to delete any file on the system, even those that they should have no access to.

Read 3 remaining paragraphs | Comments



from Ars Technica https://ift.tt/2R9U86s

Related Posts:

  • LATEST TECHNOLOGY NEWSA quirk of video compression lets spy targets see what the drone watching them sees. from Feed: All Latest http://ift.tt/2mn8NgB … Read More
  • LATEST TECHNOLOGY NEWSNow the automaker must prepare for the age of the truly driverless car. from Feed: All Latest http://ift.tt/2mkhDvD … Read More
  • LATEST TECHNOLOGY NEWSA robot that matches its ping pong-playing skill level to its human opponent's is on show at CES. from BBC News - Technology http://ift.tt/2CUnv5P … Read More
  • LATEST TECHNOLOGY NEWSScientists are learning how to predict deadly mudslides. (After fires, when enough rain comes.) The next step: Figuring out how bad they’ll be. from Feed: All Latest http://ift.tt/2Dmq5CI … Read More
  • LATEST TECHNOLOGY NEWSAs we wrap up at CES 2018, here's a peek into the massive gadget show through the lens of WIRED photographer Amy Lombard. from Feed: All Latest http://ift.tt/2EBLI1j … Read More

0 comments:

Post a Comment

Followers

Contact Form

Name

Email *

Message *

Popular Posts

FOLLOW BY EMAIL

Enter your email address:

Delivered by FeedBurner