A security researcher today disclosed on GitHub the existence of a zero-day vulnerability in Windows 10.
Zero-day vulnerabilities are often called LPE (local privilege escalation) vulnerabilities.
Hackers they can help them in later stages of attacks by enabling them to gain administrator privileges on infected devices.
According to data published on GitHub, the vulnerability is in Windows Task Scheduler. A hacker could exploit this flaw and run a malicious .job file. This could give the hacker administrator privileges, meaning they could have access to the entire system.
The vulnerability exploit was tested and appears to affect the 32-bit version of Windows 10.
However, with some changes it could affect all versions of Windows.
The researcher who published the vulnerability, known as SandboxEscaper, has published other zero-day bugs in the past. In fact, he often does so without first notifying Microsoft of their existence.
Some of the Windows zero-day vulnerabilities he has published are:
- LPE in Advanced Local Procedure Call (ALPC)
- LPE in Microsoft Data Sharing (dssvc.dll)
- LPE to ReadFile
- LPE in the Windows Error Reporting (WER) system
There have been no reports of exploitation of the last three vulnerabilities. However, the first vulnerability has been used by hackers to carry out attacks.
Since the vulnerabilities were first disclosed, Microsoft has been working to fix them. Within two months, it released patches that addressed the issues. The company's next patch is scheduled for June 11.
