{"id":167926,"date":"2026-04-08T11:12:52","date_gmt":"2026-04-08T09:12:55","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/issledovatel-slil-v-set-kod-eksplojta-dlya-windows-v-otvet-na-bezdejstvie-microsoft"},"modified":"2026-04-10T10:23:05","modified_gmt":"2026-04-10T08:23:05","slug":"issledovatel-slil-v-set-kod-eksplojta-dlya-windows-v-otvet-na-bezdejstvie-microsoft","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/issledovatel-slil-v-set-kod-eksplojta-dlya-windows-v-otvet-na-bezdejstvie-microsoft","title":{"rendered":"Un ricercatore ha pubblicato online il codice di un exploit per Windows in risposta all'inerzia di Microsoft.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Un ricercatore di sicurezza ha pubblicato online il codice di un exploit zero-day per Windows, chiamato BlueHammer. La ragione di questo passo radicale \u00e8 stato il conflitto del tecnico con il Microsoft Security Response Center (MSRC) riguardo alla gestione del processo delle informazioni da lui fornite.<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2026\/04\/2826548d95da54dac5df557db876e290.jpg\" alt=\"Un ricercatore ha pubblicato online il codice di un exploit per Windows in risposta all&#039;inerzia di Microsoft.\" \/><\/p>\n<p>Il ricercatore, noto con lo pseudonimo di Chaotic Eclipse, ha pubblicato il codice dell'exploit sulla piattaforma GitHub il 3 aprile. L'autore ha espresso delusione per l'atteggiamento della direzione del MSRC verso le informazioni da lui fornite in precedenza riguardo all'incidente e ha rifiutato di spiegare i dettagli tecnici del suo metodo per rivelare la vulnerabilit\u00e0. L'exploit consente a un attaccante locale di elevare i propri privilegi nel sistema fino al livello SYSTEM o di ottenere diritti di amministratore espansi. Nel frattempo, Microsoft non ha ancora rilasciato un aggiornamento di sicurezza, fornendo solo un commento generico sull'importanza della divulgazione coordinata delle vulnerabilit\u00e0.<\/p>\n<p>Will Dormann, principale analista di sicurezza della Tharros, ha confermato il funzionamento dell'exploit. Ha spiegato che l'attacco rappresenta un'elevazione locale dei privilegi che combina una vulnerabilit\u00e0 del tempo di controllo (Time-of-Check) con il tempo di utilizzo (Time-of-Use, TOCTOU) e confusione nei percorsi. Questo metodo complesso consente all'hacker di accedere al database Security Account Manager (SAM), dove sono memorizzati gli hash delle password degli account locali. Di conseguenza, \u00e8 possibile avviare una shell con privilegi massimi e compromettere completamente il computer.<\/p>\n<p>Allo stesso tempo, l'autore del codice Chaotic Eclipse e i tester esterni notano la presenza di bug nell'exploit, che possono rendere il suo funzionamento instabile. In particolare, sulla piattaforma Windows Server il codice non conferisce diritti sistemici completi, ma li eleva solo al livello di amministratore con richiesta di conferma. Dormann ha ipotizzato che l'insoddisfazione dell'autore possa essere stata provocata dalla richiesta di Microsoft di allegare video dimostrativi dell'exploit.<\/p>\n<p>Nonostante l'exploit richieda un accesso locale iniziale, gli hacker possono facilmente ottenerlo in anticipo attraverso ingegneria sociale o altre vulnerabilit\u00e0 nel software.<\/p>\n<p><strong>Fonte:<\/strong><\/p>\n<ul class=\"related\">\n<li><a title=\"BleepingComputer\" href=\"https:\/\/www.bleepingcomputer.com\/\" target=\"_blank\" rel=\"nofollow noopener\">BleepingComputer<\/a><\/li>\n<\/ul>\n<p><center><center><\/center><center><\/center><\/center><center><\/center><br \/>\nFonte: <a rel=\"nofollow\" href=\"https:\/\/3dnews.ru\/1139601\">3dnews.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0432\u044b\u043b\u043e\u0436\u0438\u043b \u0432 \u0441\u0435\u0442\u044c \u043a\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u043d\u0443\u043b\u0435\u0432\u043e\u0433\u043e \u0434\u043d\u044f \u0434\u043b\u044f Windows, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0435\u0433\u043e \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 BlueHammer. \u041f\u0440\u0438\u0447\u0438\u043d\u043e\u0439 \u0442\u0430\u043a\u043e\u0433\u043e \u0440\u0430\u0434\u0438\u043a\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u0448\u0430\u0433\u0430 \u0441\u0442\u0430\u043b \u043a\u043e\u043d\u0444\u043b\u0438\u043a\u0442 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0441\u0442\u0430 \u0441 \u0426\u0435\u043d\u0442\u0440\u043e\u043c \u0440\u0435\u0430\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f Microsoft (MSRC) \u0438\u0437-\u0437\u0430 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0438\u043c \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438. \u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c, \u0432\u044b\u0441\u0442\u0443\u043f\u0430\u044e\u0449\u0438\u0439 \u043f\u043e\u0434 \u043f\u0441\u0435\u0432\u0434\u043e\u043d\u0438\u043c\u043e\u043c Chaotic Eclipse, 3 \u0430\u043f\u0440\u0435\u043b\u044f \u0432\u044b\u043b\u043e\u0436\u0438\u043b \u043a\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u043d\u0430 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u0435 GitHub. \u0410\u0432\u0442\u043e\u0440 \u0432\u044b\u0440\u0430\u0437\u0438\u043b \u0440\u0430\u0437\u043e\u0447\u0430\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u043e\u0442\u043d\u043e\u0448\u0435\u043d\u0438\u0435\u043c \u0440\u0443\u043a\u043e\u0432\u043e\u0434\u0441\u0442\u0432\u0430 MSRC \u043a \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0438\u043c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":167927,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-167926","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0432\u044b\u043b\u043e\u0436\u0438\u043b \u0432 \u0441\u0435\u0442\u044c \u043a\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u043d\u0443\u043b\u0435\u0432\u043e\u0433\u043e \u0434\u043d\u044f \u0434\u043b\u044f Windows, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0435\u0433\u043e \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 BlueHammer.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/issledovatel-slil-v-set-kod-eksplojta-dlya-windows-v-otvet-na-bezdejstvie-microsoft\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0441\u043b\u0438\u043b \u0432 \u0441\u0435\u0442\u044c \u043a\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u0434\u043b\u044f Windows \u0432 \u043e\u0442\u0432\u0435\u0442 \u043d\u0430 \u0431\u0435\u0437\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0435 Microsoft | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0432\u044b\u043b\u043e\u0436\u0438\u043b \u0432 \u0441\u0435\u0442\u044c \u043a\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u043d\u0443\u043b\u0435\u0432\u043e\u0433\u043e \u0434\u043d\u044f \u0434\u043b\u044f Windows, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0435\u0433\u043e \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 BlueHammer.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/issledovatel-slil-v-set-kod-eksplojta-dlya-windows-v-otvet-na-bezdejstvie-microsoft\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-04-08T09:12:55+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-04-10T08:23:05+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47L'esploratore ha pubblicato online il codice dell'exploit per Windows in risposta all'inazione di Microsoft | ProHoster","description":"Un ricercatore di sicurezza ha pubblicato online il codice di un exploit zero-day per Windows, chiamato BlueHammer.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/issledovatel-slil-v-set-kod-eksplojta-dlya-windows-v-otvet-na-bezdejstvie-microsoft","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0441\u043b\u0438\u043b \u0432 \u0441\u0435\u0442\u044c \u043a\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u0434\u043b\u044f Windows \u0432 \u043e\u0442\u0432\u0435\u0442 \u043d\u0430 \u0431\u0435\u0437\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0435 Microsoft | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0432\u044b\u043b\u043e\u0436\u0438\u043b \u0432 \u0441\u0435\u0442\u044c \u043a\u043e\u0434 \u044d\u043a\u0441\u043f\u043b\u043e\u0439\u0442\u0430 \u043d\u0443\u043b\u0435\u0432\u043e\u0433\u043e \u0434\u043d\u044f \u0434\u043b\u044f Windows, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0435\u0433\u043e \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 BlueHammer.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/issledovatel-slil-v-set-kod-eksplojta-dlya-windows-v-otvet-na-bezdejstvie-microsoft","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-04-08T09:12:55+00:00","article:modified_time":"2026-04-10T08:23:05+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/167926","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=167926"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/167926\/revisions"}],"predecessor-version":[{"id":168278,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/167926\/revisions\/168278"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media\/167927"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=167926"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=167926"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=167926"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}