Researchers from Foxglove Security have managed to develop a super exploitby linking together three different known Windows vulnerabilities. The new exploit, which they have dubbed Hot Potato, can break almost all recent versions of Microsoft's Windows.
The Hot Potato exploit relies on three different types of attacks, some of which were discovered in 2000.
All three of these security vulnerabilities have been left unpatched by Microsoft, with the explanation that fixing them would destroy compatibility between different versions of the company's operating systems.
The three exploits that make up the single Hot Potato exploit a local NBNS (NetBIOS Name Service) spoofing technique that is 100% effective, a flaw that allows hackers to create fake WPAD (Web Proxy Auto-Discovery Protocol) proxy servers, and an attack on the Windows NTLM (NT LAN Manager) authentication protocol.
If successful, the attacker can elevate an application's privileges from the lowest level to system-level privileges.
Foxglove researchers created an exploit as a PoC (proof-of-concept) and made it available to Google's Project Zero team in 2014.They presented it at a security conference (ShmooCon) last weekend.
Additionally, the researchers uploaded some videos to YouTube demonstrating the PoC, cracking all recent versions of Windows (7, 8, 10, Server 2008, and Server 2012).
Researchers say that Windows' "Extended Protection for Authentication" feature should stop the final stage of the exploit.
Meanwhile, the exploit has already been uploaded to GitHub.
Watch the videos
