Security researcher SandboxEscaper published a zero-day vulnerability in Windows Task Scheduler on Github yesterday. He followed that up with two other vulnerabilities he found in Microsoft
As we said in the previous article, this researcher has previously disclosed the existence of zero-day vulnerabilities in Microsoft products.
Windows Error Reporting
The researcher identified the first vulnerability in Windows Error Reporting, that is, in the Windows error reporting service.
SandboxEscaper named this bug “AngryPolarBearBug2.” Last December, he had found a similar vulnerability, in the same service, which he had named “AngryPolarBearBug.”
According to SandboxEscaper, this particular vulnerability is not easy to exploit, which is a very positive thing.
However, if a malicious hacker manages to exploit it, they will gain access to the system and be able to edit files that they otherwise would not be able to. Essentially, it is an LPE vulnerability, but this one is not as dangerous.
Internet Explorer 11
The second zero-day vulnerability affects Internet Explorer 11.
According to SandboxEscaper, hackers could use this vulnerability to inject malicious code into Internet Explorer. Some security researchers who have examined the vulnerability have stated that it is not very dangerous, as it cannot be used remotely. Essentially, the vulnerability helps weaken the security of Internet Explorer, so that someone can then carry out attacks.
The list of all zero-day vulnerabilities revealed by SandboxEscaper:
- Zero-day vulnerability in Advanced Local Procedure Call (ALPC)
- Zero-day vulnerability in Microsoft Data Sharing (dssvc.dll)
- Zero-day vulnerability in ReadFile
- Zero-day vulnerability in Windows Error Reporting (WER) system
- Zero-day vulnerability in Windows Task Scheduler
- Zero-day vulnerability in Windows Error Reporting
- Zero-day vulnerability in Internet Explorer 11
SandboxEscaper stated that in the coming days he will publish two more vulnerabilities that he has identified in Microsoft.
