Microsoft Windows Privilege Escalation Vulnerability
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
A function in the task scheduler's Advanced Local Procedure Call (ALPC) interface fails to check permissions, so system files can be hijacked by any authenticated user. To exploit this vulnerability an attacker would need to obtain account credentials and device access, or use social engineering techniques to persuade a user to run malware.
The researcher who discovered the vulnerability published a proof of concept exploit on social media without allowing Microsoft the opportunity to develop an update, which means that zero-day attacks are possible at the time of publication.
For further information:
- CERT/CC Vulnerability Note VU#906424.
Remediation steps
| Type | Step |
|---|---|
|
At the time of publication there is no indication of when an update that addresses this vulnerability will be released, but this is most likely to be included in the September 2018 Patch Tuesday updates. To prevent and detect an infection in the meantime, ensure that:
It is possible to detect the proof of concept exploit using two methods:
|
Last edited: 17 February 2020 12:49 pm