• Skip to content
  • Skip to primary sidebar
  • Skip to footer
  • Gaming
  • Computing
  • Internet
  • Phone and communications
  • Software
  • Mobile computing

The source for tech buying advice

The latest technology news and reviews, covering computing, home entertainment systems, gadgets and more.

Windows 10 zero-day security hole gets publicly outed

August 29, 2018 By discountbonus_sd3n3h



A zero-day vulnerability in Windows 10 has just been made public, and it’s a hole that could potentially be exploited to take control of your PC.

The security flaw was revealed by Twitter user SandboxEscaper in controversial fashion – more on that later – and it’s a privilege escalation bug (with a proof of concept provided).

CERT/CC (the US cybersecurity organization which looks to counter emerging threats) has confirmed that this vulnerability can be leveraged against a 64-bit Windows 10 PC which has been fully patched up to date, as The Register reports.

It offers a route to gain local privilege escalation, as mentioned, meaning a malicious party could hijack the PC, but the good news – such as it is – is that it’s a local bug, so the attacker would have to be already logged into the PC to exploit it, or be running code on the machine.

However, the latter means there’s the potential avenue of getting a user to download a malicious app, and infecting the PC that way, of course. So this isn’t something that should fly under your radar – as ever, be careful what you download, and where you download it from.

Colorful revelation

SandboxEscaper revealed the bug using, shall we say, colorful language, so we won’t reproduce the tweet here, but assuming you’re not offended by profanity, you can check it out.

Suffice it to say it seems that someone got frustrated with Microsoft’s procedures for submitting bugs and vulnerabilities, and decided just to go ahead and publicly out the vulnerability instead. SandboxEscaper now seems to regret her actions, though, as she subsequently tweeted: “I screwed up, not MSFT (they are actually a cool company). Depression sucks.”

On its part, Microsoft has declared that it will “proactively update impacted devices as soon as possible”, so that means a patch is doubtless in the works, although the software giant hasn’t deemed it necessary to release any kind of emergency fix for this issue. We can probably expect the cure for the flaw to arrive in next month’s round of security updates.

Meanwhile, in other security-related news, last week Microsoft deployed a fresh batch of Intel’s microcode updates for Windows 10 which defend against the recently discovered Foreshadow vulnerability (and further variants of Spectre).

  • Some of our best laptops run Windows 10





Source link

Filed Under: Computing

Disclaimer: All the links on this page are ‘affiliate links’. This means we will earn commission from every customer we refer from this website. Our reviews are honest, we wouldn’t waste your time or put our reputation on the line by recommending anything we didn’t fully believe in.

Primary Sidebar

Disclaimer: All the links on this page are ‘affiliate links’. This means we will earn commission from every customer we refer from this website. Our reviews are honest, we wouldn’t waste your time or put our reputation on the line by recommending anything we didn’t fully believe in.

Recent Posts

Halo: The Master Chief Collection on PC might have just been leaked by Microsoft

Halo: The Master Chief Collection on PC might have just been leaked by Microsoft

It looks increasingly likely that we’ll be seeing a PC release of Halo: … [Read More...] about Halo: The Master Chief Collection on PC might have just been leaked by Microsoft

  • This Nvidia RTX 3080 crypto mining rig was built into a BMW 'just to annoy gamers'
  • Aussie GeForce Now servers confirmed for Sydney and Perth, coming mid-2021
  • Call of Duty: Mobile Season 1 start date, new modes and why it's not called Season 14

Follow Us Online

  • Facebook
  • Google+
  • LinkedIn
  • Pinterest
  • Twitter

Footer

Menus

  • Contact
  • Terms of Service
  • Privacy Policy

Most Posts

  • Samsung's Galaxy S21 Ultra packs a new type of OLED that helps boost battery life
  • Gaming
  • Computing
  • Internet
  • Phone and communications
  • Software
  • Mobile computing

Newsletter

Copyright © 2021 · WordPress · Log in