Open Menu
AllLocalCommunitiesAbout
lotide
AllLocalCommunitiesAbout
Login

Windows User Account Control Bypassed Using Character Editor to Escalate Privileges

⁨98⁩ ⁨likes⁩

Submitted ⁨⁨2⁩ ⁨days⁩ ago⁩ by ⁨cm0002@lemmy.world⁩ to ⁨cybersecurity@infosec.pub⁩

https://cybersecuritynews.com/windows-user-account-control-bypassed/

source

Comments

Sort:hotnewtop
  • frongt@lemmy.zip ⁨2⁩ ⁨days⁩ ago

    Lol “carefully crafted sequence”. This is just like back in early versions of Windows where the login screen let you open a help menu, which let you open a file picker, which let you open any file.

    Windows is a pile of shit stacked way too high.

    source
    • Brkdncr@lemmy.world ⁨1⁩ ⁨day⁩ ago

      Brah, other OS’s are full of holes too.

      source
      • wischi@programming.dev ⁨1⁩ ⁨day⁩ ago

        Whataboutism

        source
        • -> View More Comments
      • aeternum@lemmy.blahaj.zone ⁨1⁩ ⁨day⁩ ago

        tbh, there’s no decent OS. They all have issues.

        source
        • -> View More Comments
    • Alph4d0g@discuss.tchncs.de ⁨1⁩ ⁨day⁩ ago

      That sounds dangerous. I’ll keep my distance lest that pile topples.

      source
  • PleaseLetMeOut@lemmy.dbzer0.com ⁨2⁩ ⁨days⁩ ago

    TIL that ResHacking a manifest is “sophisticated” lol

    source
    • ChaosMonkey@lemmy.dbzer0.com ⁨1⁩ ⁨day⁩ ago

      This I’d not necessary for the attack. It was used to illustrate the vulnerable app manifest configuration.

      source
      • PleaseLetMeOut@lemmy.dbzer0.com ⁨1⁩ ⁨day⁩ ago

        Oh, I assumed they edited the manifest to enable the flags. Nvm then.

        source
        • -> View More Comments
    • 9point6@lemmy.world ⁨1⁩ ⁨day⁩ ago

      They don’t edit the manifest at all?

      source
  • mvirts@lemmy.world ⁨2⁩ ⁨days⁩ ago

    Lol I never knew Microsoft considers uac a convince feature not a security boundary

    source
    • ramble81@lemmy.zip ⁨1⁩ ⁨day⁩ ago

      Eh, I kinda see that point. I never considered it a boundary anyway since it didn’t require any additional authentication or authorization. It always felt more like a “here be dragons” warning for people who may not know what their doing, but if you think about it your user context never changes.

      source
      • Nighed@feddit.uk ⁨1⁩ ⁨day⁩ ago

        It has some level of additional security I think? some remote access apps have issues with them.

        source
        • -> View More Comments
    • SanctimoniousApe@lemmings.world ⁨2⁩ ⁨days⁩ ago

      Then you never thought about it - at least not in relation to who was responsible for it. I mean… because who would think that but Microsoft?

      source
  • pyre@lemmy.world ⁨1⁩ ⁨day⁩ ago

    Jesus Christ. that’s like the lock to your front door asking potential intruders to say “I’d like to enter please” to automatically unlock itself

    source