A Google security researcher discovered a bug that gives extra privileges to ordinary Windows. After 90 days of waiting and no response from Microsoft, the researcher has publicly disclosed the vulnerability.
Let's start from the beginning, a Google researcher named Forshaw discovered and disclosed a privilege escalation bug in Windows.
He contacted both Microsoft and Google to inform them of the vulnerability. Forshaw included a demonstration of the vulnerability (POC) in his update. He said he has only tested on a system with Windows 8.1 up to date and that it is unclear whether older versions, such as Windows 7, are vulnerable.
The vulnerability was found in the AhcVerifyAdminContext function. It is an internal function, not a public API, for searches on microsoft.com.
The proof of concept (PoC) includes two program files and a set of instructions to execute them. The result is that the Windows calculator runs with administrator privileges. Forshaw said that the bug is not caused by UAC, but that UAC is used in part to demonstrate the bug.
Forshaw published his disclosure privately on September 30. At the end of the post, he stated: “This bug is subject to a 90-day disclosure deadline. If 90 days pass without a widely available updated version of the code, then the bug report will automatically become publicly visible.”
