A researcher has leaked exploit code for Windows in response to Microsoft's inaction.

A security researcher has released a zero-day exploit code for Windows, dubbed BlueHammer. The reason for this radical step stemmed from a conflict the specialist had with Microsoft's Security Response Center (MSRC) regarding the handling of the information he provided.

A researcher has leaked exploit code for Windows in response to Microsoft's inaction.

The researcher, known by the pseudonym Chaotic Eclipse, posted the exploit code on GitHub on April 3rd. The author expressed frustration at MSRC's management regarding his previous information about the incident and fundamentally refused to explain the technical details of his vulnerability disclosure method. The exploit allows a local attacker to escalate their privileges in the system to SYSTEM level or gain elevated administrator rights. Currently, Microsoft has not released a security update, only providing a standard comment on the importance of coordinated vulnerability disclosure.

Will Dormann, the leading security analyst at Tharros, confirmed the exploit's functionality. He explained that the attack constitutes local privilege escalation, which combines a time-of-check to time-of-use (TOCTOU) vulnerability and path confusion. This complex method gives a hacker access to the Security Account Manager (SAM) database, where the hashes of local account passwords are stored. As a result, it is possible to launch a command shell with maximum privileges and fully compromise the computer.

At the same time, both the author of the code, Chaotic Eclipse, and independent testers note the presence of bugs in the exploit, which may cause it to operate inconsistently. In particular, on the Windows Server platform, the code does not grant full system rights but only elevates them to administrator level with a confirmation prompt. Dormann suggested that Microsoft's requirement for mandatory video attachment demonstrating the hack may have irritated the author.

Despite the fact that the vulnerability requires initial local access, hackers can easily obtain it in advance through social engineering or other software breaches.

Source:


Source: 3dnews.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster