Old Windows quirks help punch through new admin defenses
ID: 4c6b8aea-ff84-5299-84b4-a67f318c9448
STIX ID: report--4c6b8aea-ff84-5299-84b4-a67f318c9448
Feed Name: The Register (Security)
Microsoft patched nine vulnerabilities in the newly introduced Windows Administrator Protection feature disclosed by Google Project Zero researcher James Forshaw; the flaws could allow a local attacker to escalate to admin by manipulating DOS device object directory creation and impersonating a shadow admin token. The issues primarily relate to Logon Sessions and token handling and were mitigated by preventing directory creation when impersonating the shadow admin token; the feature is not yet generally available (limited to Insider Canary) and there are no reported in-the-wild exploits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
