After revealing a vulnerability in the Edge browser that Microsoft failed to patch, Google is now back with another disclosure, this time targeting the Windows 10 Fall Creators Update (version 1709) but which also affects other versions of Windows.
James Forshaw, a security researcher with Google, says the vulnerability can be exploited because of the way the operating system handles calls to Advanced Local Call Protocol (ALPC).
This means that a standard user could gain administrator privileges on a Windows 10 computer, which in the event of an attack, could ultimately lead to full control of the affected system.
But, as Neowin pointed out, this is the second bug discovered in the same function. The two vulnerabilities, codenamed 1427 and 1428, were reported to Microsoft on November 10, 2017. Microsoft said it had patched them with the February 2018 Patch release, but as it turns out, only issue 1427 was resolved.
Although the vulnerability remains unpatched, it is important to note that Microsoft does not consider it a critical flaw. According to the researcher, this is because exploiting the vulnerability involves additional steps and cannot be done remotely unless the attacker has previously gained access to the targeted systems by exploiting another flaw.
The next Windows security updates will be released on March 13th as part of the upcoming Patch Tuesday cycle, but with the vulnerability out there, Microsoft needs to hurry before more serious problems arise.
