Helvetiverse
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cm0002@lemmy.world to cybersecurity@infosec.pub · 1 month ago

Windows User Account Control Bypassed Using Character Editor to Escalate Privileges

cybersecuritynews.com

external-link
message-square
19
link
fedilink
96
external-link

Windows User Account Control Bypassed Using Character Editor to Escalate Privileges

cybersecuritynews.com

cm0002@lemmy.world to cybersecurity@infosec.pub · 1 month ago
message-square
19
link
fedilink
A sophisticated new technique that exploits the Windows Private Character Editor to bypass User Account Control (UAC) and achieve privilege escalation without user intervention, raising significant concerns for system administrators worldwide.
  • Trapped In America@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    12
    arrow-down
    2
    ·
    1 month ago

    TIL that ResHacking a manifest is “sophisticated” lol

    • ChaosMonkey@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      6
      ·
      edit-2
      1 month ago

      It is not necessary for the attack and was used to illustrate the vulnerable app manifest configuration.

      • Trapped In America@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        2
        ·
        1 month ago

        Oh, I assumed they edited the manifest to enable the flags. Nvm then.

        • shalafi@lemmy.world
          link
          fedilink
          arrow-up
          2
          ·
          1 month ago

          I thought so as well.

    • 9point6@lemmy.world
      link
      fedilink
      arrow-up
      4
      ·
      1 month ago

      They don’t edit the manifest at all?

cybersecurity@infosec.pub

cybersecurity@infosec.pub

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !cybersecurity@infosec.pub

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

  • Be kind
  • Limit promotional activities
  • Non-cybersecurity posts should be redirected to other communities within infosec.pub.

Enjoy!

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 48 users / day
  • 110 users / week
  • 368 users / month
  • 1.04K users / 6 months
  • 1 local subscriber
  • 4.98K subscribers
  • 180 Posts
  • 145 Comments
  • Modlog
  • mods:
  • shellsharks@infosec.pub
  • tweedge@infosec.pub
  • BE: 0.19.12
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org