logo

Novel Exploit Chain Enables Windows UAC Bypass

ID: 2abc5de0-76c4-5ce1-8975-e53ee93d162a

STIX ID: report--2abc5de0-76c4-5ce1-8975-e53ee93d162a

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2024-09-27

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Researchers from Fortra published a proof-of-concept for CVE-2024-6769 demonstrating a UAC bypass/privilege escalation in Windows that allows an authenticated user in the Administrators group to escalate to full SYSTEM by remapping the root drive, placing a malicious DLL to be loaded by ctfmon.exe, and poisoning the activation context cache; Microsoft disputes that this constitutes a vulnerability, arguing it falls under intended non-robust security boundaries, while Fortra warns of the serious potential impact for administrator accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.