Microsoft has been going through some tough times lately . And just when it seemed like October couldn't get any worse for the company, a new zero-day vulnerability discovered by a researcher that can be exploited to delete files proves otherwise.
As Bleeping Computer, the vulnerability, which affects all versions of Windows 10, can be used to exploit system data and can also lead to privilege escalation (an exploit technique for gaining access to protected resources on the computer).
According to researcher SandboxEscaper, the issue concerns Microsoft's Microsoft Data Sharing Service, which provides a data interface between applications. In a tweet, the researcher shared a GitHub as a proof-of-concept.
The zero-day vulnerability can be used to delete application DLLs, forcing programs to search for missing libraries in other locations. Once the search reaches a location that grants write permission to the local user, the attacker could take advantage by providing a malicious DLL.
While the bug may seem serious, the same researcher says the flaw is “low-quality and difficult to exploit.” While we’re still waiting for Microsoft to address the issue, 0patch has released a temporary patch to block the vulnerability until the company does something about it.
