{"id":304584,"date":"2021-07-21T17:49:12","date_gmt":"2021-07-21T14:49:12","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/windows-10-11-vulnerability-exposes-admin-passwords-to-local-users\/"},"modified":"2021-07-21T17:49:12","modified_gmt":"2021-07-21T14:49:12","slug":"windows-10-11-vulnerability-exposes-admin-passwords-to-local-users","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/windows-10-11-vulnerability-exposes-admin-passwords-to-local-users\/","title":{"rendered":"#Windows 10\/11 vulnerability exposes admin passwords to local users"},"content":{"rendered":"<p>&#8220;<strong>#Windows 10\/11 vulnerability exposes admin passwords to local users<\/strong>&#8221;<\/p>\n<div>\n<div class=\"article-gallery lightGallery\">\n<div data-thumb=\"https:\/\/scx1.b-cdn.net\/csz\/news\/tmb\/2021\/vulnerability.jpg\" data-src=\"https:\/\/scx2.b-cdn.net\/gfx\/news\/hires\/2021\/vulnerability.jpg\" data-sub-html=\"Credit: Pixabay\/CC0 Public Domain\">\n<figure class=\"article-img\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/scx1.b-cdn.net\/csz\/news\/800a\/2021\/vulnerability.jpg\" alt=\"vulnerability\" title=\"Credit: Pixabay\/CC0 Public Domain\" width=\"800\" height=\"511\"\/><figcaption class=\"text-darken text-low-up text-truncate-js text-truncate mt-3\">\n                Credit: Pixabay\/CC0 Public Domain<br \/>\n            <\/figcaption><\/figure>\n<\/div>\n<\/div>\n<p>A <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/jonasLyk\/status\/1417205166172950531\">Twitter user<\/a> has found and made public a Windows 10\/11 vulnerability that exposes admin passwords to local users who can then escalate their privileges up to admin, giving them total system access. As he notes on his posts, he found that Windows Security Account Manager (SAM) data could be read by users with very limited privileges, giving them access to admin passwords. Microsoft <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>arently caught wind of the vulnerability and posted an Executive Summary of the issue on its <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-36934\">Security Vulnerability page<\/a>.<\/p>\n<p>                                                                                The <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">news<\/a> of a new vulnerability in the Windows operating system is not good for Microsoft, coming just weeks after warnings about the PrintNightmare vulnerability in Windows Print Spooler. Microsoft says this new vulnerability is a result of inadequate protection of access control lists on several system files, which include the SAM database. They further note that an unauthorized person could use the vulnerability to run custom code that takes advantage of higher system privileges and could add, change or delete user data. They conclude by noting that unauthorized users would need to have the ability to run code on such systems to be able to take advantage of the vulnerability.<\/p>\n<p>Others on <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">Twitter<\/a> and elsewhere have noted the vulnerability exists only for systems running build 1809 of Windows 10 and some versions of Windows 11. They note also that in addition to allowing access to SAM data, the vulnerability also allows access to certain system and security files. For a nefarious person to take advantage of the vulnerability, the system must have a VSS shadow copy of the system drive. This copy may exist on user systems due to inadvertent actions they may have taken, such as installing a hard drive that holds more than 128GB and then conducting a Windows update. Adding an installer package file format called MSI will do so, as well. Users who want to know if their system has the vulnerability can run the system command vssadmin.<\/p>\n<p>Microsoft notes that they will update customers as they learn more. No timeline for a patch has yet been announced.\n                                                                                                                        <\/p>\n<hr\/>\n<div class=\"article-main__explore my-4 d-print-none\">\n<p>                                            Microsoft warns of PrintNightmare vulnerability due to flaw in Windows Print Spooler\n                                        <\/p><\/div>\n<hr class=\"mb-4\"\/>\n<div class=\"article-main__more p-4\">\n                                                                                                <strong>More information:<\/strong><br \/>\n                                                <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-36934\">msrc.microsoft.com\/update-guid \u2026 ility\/CVE-2021-36934<\/a><\/p><\/div>\n<p class=\"article-main__note mt-4\">\n                                                \u00a9 2021 <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/sciencee\/\" data-internallinksmanager029f6b8e52c=\"5\" title=\"Science\" target=\"_blank\" rel=\"noopener\">Science<\/a> X Network<\/p>\n<p>                                        <!-- print only --><\/p>\n<div class=\"d-none d-print-block\">\n<p>                                                 <strong>Citation<\/strong>:<br \/>\n                                                 Windows 10\/11 vulnerability exposes admin passwords to local users (2021, July 21)<br \/>\n                                                 retrieved 21 July 2021<br \/>\n                                                 from https:\/\/techxplore.com\/news\/2021-07-windows-vulnerability-exposes-admin-passwords.html<\/p>\n<p>                                            This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no<br \/>\n                                            part may be reproduced without the written permission. The content is provided for information purposes only.<\/p><\/div>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script id=\"facebook-jssdk\" async=\"\" src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js\"><\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more Like this articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/science\/\" target=\"_blank\" rel=\"noopener\">Science category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/techxplore.com\/news\/2021-07-windows-vulnerability-exposes-admin-passwords.html\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Windows 10\/11 vulnerability exposes admin passwords to local users&#8221; Credit: Pixabay\/CC0 Public Domain A Twitter user has found and made public a Windows 10\/11 vulnerability that exposes admin passwords to local users who can then escalate their privileges up to admin, giving them total system access. As he notes on his posts, he found that&#8230;<\/p>\n","protected":false},"author":1,"featured_media":304585,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/scx2.b-cdn.net\/gfx\/news\/hires\/2021\/vulnerability.jpg","fifu_image_alt":"","footnotes":""},"categories":[16],"tags":[],"class_list":["post-304584","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sciencee"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/304584","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=304584"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/304584\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/304585"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=304584"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=304584"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=304584"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}