Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit
ID: 793308fb-d7fd-5ecb-a1b4-a322bf84a59e
STIX ID: report--793308fb-d7fd-5ecb-a1b4-a322bf84a59e
Feed Name: Bleeping Computer
Threat Score
A disgruntled researcher published a public proof-of-concept called "BlueHammer" for an unpatched Windows local privilege escalation (LPE) zero-day that combines a TOCTOU and path confusion to access the Security Account Manager (SAM) and escalate to SYSTEM. The exploit code was posted on GitHub, is reportedly buggy but has been confirmed to work in at least some cases by researchers, and Microsoft had not released a patch at time of reporting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
