Microsoft Investigating Windows Proof-of-Concept Flaw

Microsoft noted last week that its security team is looking into an elevation-of-privilege exploit affecting Windows-based systems.

The company released very little information, except for a brief Nov. 24 notice on its Twitter security response page. The flaw was disclosed after someone posted proof-of-concept code on a "programming education site," according to Chester Wisniewski, senior security advisor at Sophos Canada, in a blog post. The code was subsequently removed, he noted.

The flaw enables elevation-of-privilege from a local user account level to the system account level. It also bypasses the user account control (UAC) protection found in Windows Vista and Windows 7, Wisniewski explained. He described it as a Win32k.sys bug.

"The flaw is related to the way in which a certain registry key is interpreted and enables an attacker to impersonate the system account, which has nearly unlimited access to all components of the Windows system," he wrote in the blog.

In addition to Vista and Windows 7, other Windows operating systems (both 32-bit and 64-bit) are subject to the flaw, including Windows XP, Windows Server 2008 and Windows Server 2003, according to a post by Prevx blogger Marco Giuliani. He explained that the flaw cannot be exploited via remote code execution.

"It is a local privilege escalation exploit," Giuliani wrote. "This means that the potential malware must be already in the target machine to exploit this flaw." However, he described it as a critical flaw because it enables the local user to gain administrative privileges.

Microsoft hasn't rated the exploit nor said when, or if, it would provide a fix. Both antimalware vendors offered some advice in their blogs to avoid the zero-day flaw. The advice includes altering the registry for standard users or downloading security software.

About the Author

Kurt Mackie is senior news producer for 1105 Media's Converge360 group.

Featured

  • The First Steps of Establishing Your Cloud Security Strategy

    In this guide, we'll identify some first steps you can take to establish your cloud security strategy. We'll do so by discussing the cloud security impact of individual, concrete actions featured within the CIS Critical Security Controls® (CIS Controls®) and the CIS Benchmarks™.

  • Human Error Remains the Leading Cause of Cloud Data Breaches

    Human error is still one of the biggest threats to cloud security, despite all the technology bells and whistles and alerts and services out there, from multi-factor authentication, to social engineering training, to enterprise-wide integrated cybersecurity platforms, and more.

  • Abstract illustration of a human news reporter interviewing an AI with a microphone

    AI on AI in Education: A Dialogue

    Scholars are doing lots of asking and predicting about the risks and rewards of generative artificial intelligence in school, but has anyone asked the all-knowing chatbots?

  • Pattern of desks with interconnected circles, triangles, and lines

    Classroom Furniture Giveaway Seeks Dream Learning Space Design

    Educators have a chance to design their ideal K-12 learning space in a contest recently announced by classroom furniture manufacturer KI.