{"id":371463,"date":"2021-11-23T23:13:14","date_gmt":"2021-11-23T20:13:14","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/new-windows-zero-day-grants-local-admin-access\/"},"modified":"2021-11-23T23:13:14","modified_gmt":"2021-11-23T20:13:14","slug":"new-windows-zero-day-grants-local-admin-access","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/new-windows-zero-day-grants-local-admin-access\/","title":{"rendered":"#New Windows Zero-Day Grants Local Admin Access"},"content":{"rendered":"<p><strong>&#8220;#New Windows Zero-Day Grants Local Admin Access&#8221;<\/strong><\/p>\n<div id=\"post-770873\">\n<div class=\"entry-content e-content\">\n<figure style=\"width: 1200px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"type:primaryImage size-full wp-image-747705\" srcset=\"https:\/\/www.howtogeek.com\/wp-content\/uploads\/2021\/08\/hacker-with-laptop.jpg?width=398&amp;trim=1,1&amp;bg-color=000&amp;pad=1,1 400w, https:\/\/www.howtogeek.com\/wp-content\/uploads\/2021\/08\/hacker-with-laptop.jpg?width=1198&amp;trim=1,1&amp;bg-color=000&amp;pad=1,1 1200w\" sizes=\"auto, 400w, 1200w\" src=\"https:\/\/www.howtogeek.com\/wp-content\/uploads\/2021\/08\/hacker-with-laptop.jpg?width=1198&amp;trim=1,1&amp;bg-color=000&amp;pad=1,1\" alt=\"Hacker with a laptop\" width=\"1200\" height=\"675\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><figcaption class=\"wp-caption-text\"><span class=\"type:primaryImage imagecredit\"><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.shutterstock.com\/image-photo\/male-hacker-652144957\">ViChizh\/Shutterstock.com<\/a><\/span><\/figcaption><\/figure>\n<p>It seems like there\u2019s a new local zero-day exploit that grants admin privileges on Windows almost every day, and today is no exception. A researcher publically disclosed a vulnerability that lets anyone with standard privileges open a command prompt with\u00a0SYSTEM level access.<\/p>\n<p>With this vulnerability, threat actors could go through the elevated command prompt to\u00a0elevate their privileges and grant far more access than they\u2019re meant to have. Someone can gain access to a system running Windows 10, Windows 11, and Windows Server 2022.<\/p>\n<p>The exploit was discovered by researcher\u00a0Abdelhamid Naceri and published on <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/github.com\/klinix5\/InstallerFileTakeOver\">GitHub<\/a>. To verify the issue,\u00a0<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/new-windows-zero-day-with-public-exploit-lets-you-become-an-admin\/\">BleepingComputer<\/a> tested it on a Windows PC running Windows 10 21H1 build 19043.1348 and found that it \u201conly took a few seconds to gain SYSTEM privileges from a test account with \u2018Standard\u2019 privileges.\u201d<\/p>\n<p>When asked by BleepingComputer why he chose to publicly disclose the vulnerability instead of reporting it to Microsoft\u2019s bug bounty program, he cited massively decreased payouts for reporting issues.\u00a0\u201cMicrosoft bounties has been trashed since April 2020, I really wouldn\u2019t do that if MSFT didn\u2019t take the decision to downgrade those bounties,\u201d explained Naceri.<\/p>\n<p>As this is a local exploit, the person would need to access your computer in person. However, as mentioned, it only takes a few seconds for them to get elevated access, so they won\u2019t need to be in possession for long. This is an issue you\u2019ll want to watch out for, and make sure to <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">download<\/a> the patch as soon as Microsoft makes one available.<\/p>\n<p><strong>RELATED:<\/strong> <strong><em>Steel<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/watch-movies-tv-seriess\/\" data-internallinksmanager029f6b8e52c=\"8\" title=\"Watch Movies &amp; TV Series\" target=\"_blank\" rel=\"noopener\">Series<\/a> Software Bug Gives Windows 10 Admin Rights<\/em><\/strong><\/p>\n<\/div>\n<p><!-- .entry-content --><br \/>\n<!-- .entry-footer -->\n<\/div>\n<p><script>\n setTimeout(function(){\n  !function(f,b,e,v,n,t,s)\n  {if(f.fbq)return;n=f.fbq=function(){n.callMethod?\n  n.callMethod.apply(n,arguments):n.queue.push(arguments)};\n  if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';\n  n.queue=[];t=b.createElement(e);t.async=!0;\n  t.src=v;s=b.getElementsByTagName(e)[0];\n  s.parentNode.insertBefore(t,s) } (window, document,'script',\n  'https:\/\/connect.facebook.net\/en_US\/fbevents.js');\n   fbq('init', '335401813750447');\n   fbq('track', 'PageView');\n  },3000);\n<\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/www.howtogeek.com\/770873\/new-windows-zero-day-grants-local-admin-access\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#New Windows Zero-Day Grants Local Admin Access&#8221; ViChizh\/Shutterstock.com It seems like there\u2019s a new local zero-day exploit that grants admin privileges on Windows almost every day, and today is no exception. A researcher publically disclosed a vulnerability that lets anyone with standard privileges open a command prompt with\u00a0SYSTEM level access. With this vulnerability, threat actors&#8230;<\/p>\n","protected":false},"author":1,"featured_media":371464,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.howtogeek.com\/wp-content\/uploads\/2021\/08\/hacker-with-laptop.jpg?height=200p&trim=2,2,2,2","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-371463","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/371463","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=371463"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/371463\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/371464"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=371463"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=371463"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=371463"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}