logo

Old Windows quirks help punch through new admin defenses

ID: 4c6b8aea-ff84-5299-84b4-a67f318c9448

STIX ID: report--4c6b8aea-ff84-5299-84b4-a67f318c9448

Feed Name: The Register (Security)

Threat Score
50/100

Date Published: 2026-01-28

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Microsoft patched nine vulnerabilities in the newly introduced Windows Administrator Protection feature disclosed by Google Project Zero researcher James Forshaw; the flaws could allow a local attacker to escalate to admin by manipulating DOS device object directory creation and impersonating a shadow admin token. The issues primarily relate to Logon Sessions and token handling and were mitigated by preventing directory creation when impersonating the shadow admin token; the feature is not yet generally available (limited to Insider Canary) and there are no reported in-the-wild exploits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.