Experts published unpatched Windows zero-day BlueHammer
ID: 290ef683-bde1-5984-9961-9fc514692a4b
STIX ID: report--290ef683-bde1-5984-9961-9fc514692a4b
Feed Name: Security Affairs
Threat Score
## Executive summary The report details the public disclosure of "BlueHammer," an unpatched Windows zero-day local privilege escalation (LPE) combining TOCTOU and path confusion, whose GitHub proof-of-concept (published by the researcher "Nightmare-Eclipse") can allow local attackers to access the SAM database and escalate to SYSTEM; Microsoft has not released a patch and the disclosure followed a dispute over MSRC handling of the report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
