Hacker Leaked New Unpatched Windows Zero-day Vulnerability POC Online

A Security researcher posted new windows Zero-day vulnerability POC online that contain exploit code that allow attacker to read any file in the vulnerable windows system.

Sanboxescaper, pseudonym of Twitter handler & an unknown hacker leaked a Proof-of-concept for unpatched windows zero-day vulnerability exploit via her twitter feed.

Sanboxescaper already leaked 2 zero-day flow online, one could allow
an attacker to exploit the Advanced Local Procedure Call (ALPC) interface to get system privileges and another Vulnerability allows attackers to delete files from vulnerable windows.

In this case, vulnerability affected the ReadFile.exe, A windows functions that help to reads data from the specified file or input/output (I/O) device.

This exploit falls under the privilege escalation vulnerability that allows let local attackers gain access to functions and permissions to read any file which can be accessed only by an admin level user privilege.

This Vulnerability existing in the MsiAdvertiseProduct, a function generates an advertise script or advertises a product to the computer.

According to Microsoft document, the MsiAdvertiseProduct function enables the installer to write to a script the registry and shortcut information used to assign or publish a product.

Researchers said, it leads to abuse the installer service due to improper validation affected function that force installer to read any privileged system files make a copy of it.

This POC exploit acknowledged by 0patch and confirmed this POC to work and in fact provide read access to a chosen file that the initiating user didn’t have read access to.

Also she said., My github got taken down. And screw it, I’m not going to get anything for this bug anymore.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Balaji

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

GitVenom Campaign Abuses Thousands of GitHub Repositories to Infect Users

The GitVenom campaign, a sophisticated cyber threat, has been exploiting GitHub repositories to spread malware…

4 hours ago

UAC-0212: Hackers Unleash Devastating Cyber Assault on Critical Infrastructure

In a recent escalation of cyber threats, hackers have launched a targeted campaign, identified as…

4 hours ago

Widespread Chrome Malware: 16 Extensions Infect Over 3.2 Million Users

A recent cybersecurity investigation has uncovered a cluster of 16 malicious Chrome extensions that have…

4 hours ago

Sliver C2 Server Vulnerability Enables TCP Hijacking for Traffic Interception

A significant vulnerability has been discovered in the Sliver C2 server, a popular open-source cross-platform…

4 hours ago

TSforge New Tool Bypasses Windows Activation on All Versions

A significant breakthrough in bypassing Windows activation has been achieved with the introduction of TSforge,…

5 hours ago

Cybercriminals Impersonate Windows “Commander Tool” to Launch LummaC2 Malware Attack

The AhnLab Security Intelligence Center (ASEC) has uncovered a new cyberattack campaign leveraging the LummaC2…

5 hours ago