Microsoft looks into Windows privilege escalation exploit

Microsoft is tracking a newly discovered zero-day exploit in Windows that can be leveraged to bypass privilege protections to obtain full system control.

The publicly posted exploit works on Vista and Windows 7 systems, according to a blog post from Marco Giuliani, malware technology specialist at security firm Prevx. The vulnerability also affects Windows XP and Server 2008 and 2003.

What makes the bug alarming is that it can be used to run authorized software or programs, even on machines that do not run with administrator rights or contain User Access Control, a feature introduced in Vista that enables administrators to set rights so users can run most applications but with limited privileges.

"Using a limited account gives [users] a great advantage versus malware because it limits the vulnerable surface the malware can damage," Giuliani wrote. "This 0-day exploit allows malware that has already been dropped on the system to bypass these limitations and get the full control of the system."

Microsoft is investigating the vulnerability. Patches from the software giant are next due out on Dec. 14.

"Because this is a local elevation-of-privilege issue, it requires attackers to be already able to execute code on a targeted machine,"  Jerry Bryant, group manager of response communications at Microsoft, said in a statement sent to SCMagazineUS.com on Monday. "We will continue to investigate the issue and, when done, we will take appropriate action to protect our customers and the internet ecosystem. Microsoft takes any reports of vulnerabilities in our products seriously.

Meanwhile, public exploit code also has emerged for another unpatched Microsoft privilege-escalation bug, this one specific to Stuxnet attacks.

Microsoft first warned about the flaw in September but has yet to deliver a patch.

Sign up to our newsletters

More in News

House Intelligence Committee OKs amended version of controversial CISPA

Despite the 18-to-2 vote in favor of the bill proposal, privacy advocates likely will not be satisfied, considering two key amendments reportedly were shot down.

Judge rules hospital can ask ISP for help in ID'ing alleged hackers

The case stems from two incidents where at least one individual is accused of accessing the hospital's network to spread "defamatory" messages to employees.

Three LulzSec members plead guilty in London

Ryan Ackroyd, 26; Jake Davis, 20; and Mustafa al-Bassam, 18, who was not named until now because of his age, all admitted their involvement in the hacktivist gang's attack spree.