0Day on Twitter! Not in underground forums, or on the Darkweb, but freely on Twitter and Github (now owned by Microsoft).
A big surprise awaited Microsoft when they announced that a zero-day Windows vulnerability was freely circulating on Twitter. The vulnerability allows an attacker to gain system privileges on the victim’s computer. 
The tweet came from the account @SandboxEscaper. As you can see in the image below, the researcher also posted a link to Github that contained everything needed for a successful PoC. 
Of course, the Git link no longer exists, and it is surprising that the announcement on Twitter is still there.
CERT researcher Phil Dormann confirmed the bug on Twitter and explained that it worked on a “fully updated system with Windows 10 64bit.”
A post on CERT provides more details about the vulnerability, but emphasizes that there is no update yet for the affected systems.
Microsoft, for its part, told The Registry that it is preparing a patch that will probably be released on the next Patch Tuesday, which is September 11th. The company probably adheres to its employees' working hours very strictly and does not allow overtime even if millions of systems are at risk.
As it seems, all versions of Windows 10 are affected, regardless of whether they have been updated or not. Older versions of Windows, (Windows 7 and Windows 8.1), do not seem to be affected by this particular vulnerability.
As for the security of your system and until Microsoft decides to release the update to close the 0Day gap (by the book on the next Patch Tuesday), it would be a good idea to avoid downloading and running applications and files from untrusted sources.
_________________________________
- Keeper: lawsuit for publishing vulnerability
- Modified NSA exploits now work on Windows 10
- Debian: A comprehensive guide to everything in Greek
- SUSE new customized Kernel especially for Microsoft Azure
