A security researcher posted details about a vulnerability in the Windows operating system on Twitter 
The vulnerability is a “local privilege escalation” issue that allows an attacker to elevate malicious code access from a restricted USER to an all-access SYSTEM account.
Will Dormann, an engineer at CERT/CC, has confirmed the vulnerability and issued an official notice last night.
Dormann says the vulnerability lies in the Windows Task Scheduler and more specifically in the Advanced Local Procedure Call (ALPC) interface.
The ALPC interface is an internal Windows mechanism that acts as an inter-process communication system. ALPC allows a client process running within the operating system to request a server process running within the same operating system to provide some information or perform some action.
The researcher, known as SandboxEscaper, released proof-of-concept (PoC) code on GitHub for exploiting the ALPC interface through which one gains SYSTEM access to a Windows system.
Malware authors would be particularly interested in this PoC, as it allows malware to gain administrator access to targeted systems using a more reliable vulnerability than many existing exploitation methods.
SandboxEscaper has not notified Microsoft of the vulnerability, which means there is no patch for this flaw. Currently, all Windows users are vulnerable.
Microsoft's next security updates are scheduled for September 11th.
The researcher has also deleted his Twitter account after the vulnerability was revealed.
