Windows Zero-Day Vulnerability Comes With PoC on GitHub
បានផ្សាយនៅ: 29 សីហា 2018 · បន្ទប់ព័ត៌មាន · 1 នាទីអាន

A new zero-day vulnerability was recently made public following a Tweet from @SandboxEscaper, who claimed to be frustrated with Microsoft and, apparently, their bug submission process.
The tweet included a link to the proof-of-concept for the alleged zero-day vulnerability on GitHub, prompting security researchers to download and test @SandboxEscaper’s claims.
Following an assessment by CERT/CC vulnerability analyst Phil Dormann, the bug was verified and confirmed to be working on a fully-patched 64-bit Windows 10 machine, enabling attackers to gain admin privileges if exploited.
It’s unclear if the zero-day would work on all Microsoft supported Windows versions, including 32-bit ones, but it’s definitely cause for concern, since the PoC is publicly available and can easily be weaponized by threat actors.
While the zero-day does require some specific conditions for execution – an attacker needs the victim to download and execute a tainted application for the vulnerability to be exploited, an attack vector that is not uncommon, especially with APTs (Advanced Persistent Threats) and spearphishing.
“Microsoft Windows task scheduler contains a local privilege escalation vulnerability in the Advanced Local Procedure Call (ALPC) interface, which can allow a local user to obtain SYSTEM privileges,” reads the CERT/CC advisory. “The CERT/CC is currently unaware of a practical solution to this problem.”
While it’s uncertain whether Microsoft had been previously notified by @SandboxEscaper regarding the zero-day, the tweet does suggest that an interaction with Microsoft caused some friction.
Following the incident, a Microsoft spokesperson claims the company will “proactively update impacted devices as soon as possible,” potentially during a Patch Tuesday release.
Cr. Bitdefender
សាកល្បង Bitdefender ឥតគិតថ្លៃ 30 ថ្ងៃ
ការការពារដែលឈ្នះពានរង្វាន់សម្រាប់ឧបករណ៍ទាំងអស់របស់អ្នក។
ទទួលឥឡូវនេះអត្ថបទពាក់ព័ន្ធ

ការពារក្រុមគ្រួសាររបស់អ្នកពីការបោកប្រាស់តាមរយៈសំឡេង AI "កូនយំ"
បានផ្សាយនៅ: 21 កក្កដា 2026
អានអត្ថបទ
តើការលេចធ្លាយទិន្នន័យ (Data Breach) គឺជាអ្វី? ហើយហេតុអ្វីបានជា Bitdefender គឺជាដំណោះស្រាយដែលមានសុវត្ថិភាពបំផុត?
បានផ្សាយនៅ: 19 កក្កដា 2026
អានអត្ថបទ
រដូវកាលបាល់ទាត់ហ្វាស៊ីន៖ កុំបណ្តោយឱ្យជនបោកប្រាស់ស៊ុតបញ្ចូលទីបំផ្លាញសុវត្ថិភាពឌីជីថលរបស់អ្នក
បានផ្សាយនៅ: 15 មិថុនា 2026
អានអត្ថបទ
អ្នកប្រើប្រាស់ Android ត្រូវតែមើលបន្ទាន់! វិធីសាស្រ្តកំណត់ចាក់សោទូរស័ព្ទទាំង ៣ ដើម្បីការពារកម្មវិធីលួចលុយអស់ពីគណនី (បច្ចុប្បន្នភាពចុងក្រោយ)
បានផ្សាយនៅ: 12 មិថុនា 2026
អានអត្ថបទ
ហេគឃ័រមិនមែនសំដៅតែលើក្រុមហ៊ុនធំៗនោះទេ គឺអាជីវកម្មរបស់អ្នកហើយជាគោលដៅបន្ទាប់
បានផ្សាយនៅ: 29 ឧសភា 2026
អានអត្ថបទ