In Windows, a new series of vulnerabilities that allows access to the system. A user under the pseudonym SandBoxEscaper presented exploits for three flaws. The first allows elevating user privileges within the system by using the task scheduler. An authorized user can increase their rights to system level.

The second flaw affects the error reporting service in Windows. This allows attackers to modify files that are typically inaccessible. Finally, the third exploit leverages a vulnerability in Internet Explorer 11, enabling the execution of JavaScript code with higher privileges than usual.
And while all these exploits require direct access to the PC, the mere existence of these flaws is concerning. They pose a particular danger if the user becomes a victim of phishing or other similar online fraud methods.
It is noted that independent testing of the exploits showed that they work on both 32-bit and 64-bit versions of the OS. Recall that in March, Google reported that a vulnerability related to privilege escalation in older versions of Windows was exploited through the Chrome browser.
Microsoft has not commented on the information yet, so it is unclear when a patch will be available. An official statement from Redmond is expected within the next few days, so we just have to wait.
Source: 3dnews.ru
