Security Researcher revealed an unpatched Windows Zero-day vulnerability exploit online that discovered in Microsoft Windows Task Scheduler.
This vulnerability discovered and exposed by Belgium security researcher in Twitter under the handle name of “SandboxEscaper“.
She mentioned as “Here is the alpc bug as 0day. I don’t f**king care about life anymore. Neither do I ever again want to submit to MSFT anyway. F**k all of this shit.”
It is a local privilege escalation vulnerability in the Microsoft Windows task scheduler in the handling of ALPC(Advanced Local Procedure Call) interface which allows the local user to gain SYSTEM privileges.
Experts from CERT/CC analyze this vulnerability and confirm that the exploit which is released in public works on 64-bit Windows 10 and Windows Server 2016 systems.
A Microsoft spokesperson confirmed that the company recognizes the issue and will “proactively update impacted advice as soon as possible.
The vulnerability note from CERT/CC says: “Theis currently unaware of a practical solution to this problem.”
According to the Tweet that set the hounds running, it’s a zero-day with a proof-of-concept at GitHub. Also, you can see here the complete PoC tutorial for this exploit and how it works in Windows.
So at this time, all Windows users are vulnerable to this local privilege escalation vulnerability and Microsoft scheduled September 11 for next patch Tuesday, so we can expect the fixed in next Microsoft security update.
Zerodium Pays Upto $1,500,000 Per Fully Functional Zeroday Exploit Submissions
Adobe Issues Patch for Critical Flash Player Zero-day Vulnerability : Its Time to Update
Zero-Day Remote Code Execution Vulnerability Discovered in Microsoft Windows JScript
New Double Zero-day Exploit Discovered in same PDF file that Affected Adobe Acrobat & Windows 7
Cybersecurity firm Bitdefender has patched a severe flaw (CVE-2025-2244) in its GravityZone Console, which could…
The National Initiative for Cybersecurity Education (NICE) Workforce Framework for Cybersecurity has undergone a significant…
As cyber threats grow increasingly sophisticated, traditional security tools often fall short in providing comprehensive…
Cybersecurity researcher "0xdf" has cracked the "Ghost" challenge on Hack The Box (HTB), a premier…
Google has unveiled Sec-Gemini v1, an AI model designed to redefine cybersecurity operations by empowering…
The United States has successfully extradited two Kosovo nationals, Ardit Kutleshi, 26, and Jetmir Kutleshi,…