w9r.de
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cm0002@lemmy.world to cybersecurity@infosec.pub · 3 days ago

Windows User Account Control Bypassed Using Character Editor to Escalate Privileges

cybersecuritynews.com

external-link
message-square
19
link
fedilink
96
external-link

Windows User Account Control Bypassed Using Character Editor to Escalate Privileges

cybersecuritynews.com

cm0002@lemmy.world to cybersecurity@infosec.pub · 3 days ago
message-square
19
link
fedilink
A sophisticated new technique that exploits the Windows Private Character Editor to bypass User Account Control (UAC) and achieve privilege escalation without user intervention, raising significant concerns for system administrators worldwide.
  • Trapped In America@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    12
    arrow-down
    2
    ·
    3 days ago

    TIL that ResHacking a manifest is “sophisticated” lol

    • ChaosMonkey@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      6
      ·
      edit-2
      3 days ago

      It is not necessary for the attack and was used to illustrate the vulnerable app manifest configuration.

      • Trapped In America@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        2
        ·
        3 days ago

        Oh, I assumed they edited the manifest to enable the flags. Nvm then.

        • shalafi@lemmy.world
          link
          fedilink
          arrow-up
          2
          ·
          3 days ago

          I thought so as well.

    • 9point6@lemmy.world
      link
      fedilink
      arrow-up
      4
      ·
      3 days ago

      They don’t edit the manifest at all?

cybersecurity@infosec.pub

cybersecurity@infosec.pub

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !cybersecurity@infosec.pub

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

  • Be kind
  • Limit promotional activities
  • Non-cybersecurity posts should be redirected to other communities within infosec.pub.

Enjoy!

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 46 users / day
  • 477 users / week
  • 824 users / month
  • 2.12K users / 6 months
  • 1 local subscriber
  • 4.76K subscribers
  • 1.05K Posts
  • 1.89K Comments
  • Modlog
  • mods:
  • shellsharks@infosec.pub
  • tweedge@infosec.pub
  • BE: 0.19.12
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org