HomeSecurityWindows 7/8/8.1/10 are at risk from the Hot Potato exploit!

Windows 7/8/8.1/10 are at risk from the Hot Potato exploit!

Windows 7/8/8.1/10 are at risk from the Hot Potato exploit !

Windows versions 7, 8, 10, Server 2008 and Server 2012 are vulnerable to the Hot Potato exploit, which allows hackers to gain complete control of a PC or laptop.

Windows 7/8/8.1/10 are at risk from the Hot Potato exploit!

Security researchers from Foxglove Security have discovered that almost all recent versions of Microsoft's operating system, Windows, are vulnerable to a privilege escalation exploit.

By chaining together a series of known Windows security vulnerabilities, researchers from Foxglove Security have discovered a way to compromise PCs/systems/laptops running Windows 7/8/8.1/10 and Windows Server 2008/2010.

https://www.secnews.gr/100620/iphone-crash/See also: WARNING! Link is circulating that crashes & reboots your iPhone!

Foxglove researchers have named the exploit 'Hot Potato'. 'Hot Potato' is based on three different types of attacks, some of which were discovered quite a while back… at the beginning of the new millennium, in 2000. By linking these together, hackers can remotely gain full access to PCs/laptops running the above versions of Windows.
Surprisingly, some of the exploits found in 2000 have not yet been patched by Microsoft, with the excuse that by patching them, the company would break compatibility between different versions of the operating system.

Hot Potato is a set of three different security issues in the Windows operating system. One of the flaws is a local NBNS (NetBIOS Name Service) spoofing technique that is 100% effective. Potential hackers can use this flaw to create fake WPAD (Web Proxy Auto-Discovery Protocol) proxy servers, and an attack against the Windows NTLM (NT LAN Manager) authentication protocol.

Exploiting these exploits in a chained manner allows hackers to gain access to the PC/laptop, escalating and gaining the privileges of an application from the lowest rank to system-level privileges.

https://www.secnews.gr/100636/skype-finally-hides-users-ip-address/btn-large” variation=”btn-info”]Read also: Skype finally hides the IP addresses of its users!

The Foxglove researchers built their exploit on proof-of-concept code released by Google's Project Zero team in 2014 and presented their findings at the ShmooCon security conference last weekend.
They have also posted proof-of-concept videos on YouTube, showing the researchers cracking Windows versions 7, 8, 10, Server 2008, and Server 2012.

You can enjoy them:

[su_youtube url=”https://youtu.be/Nd6f5P3LSNM” width=”580″ height=”380″]

 

[su_youtube url=”https://youtu.be/z_IGPWgL5SY” width=”580″ height=”380″]

 

[su_youtube url=”https://youtu.be/Kan58VeYpb8″ width=”580″ height=”380″]

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS