Interesting question, is this a UAC bypass? My first thought is no, because UIPI means you can't automate the interaction. Therefore, the only way to exploit it is if you could have just clicked OK in the UAC consent anyway.... right? (yes, I know UAC is not a supported boundary)https://twitter.com/harr0ey/status/1211075032400760832 …
-
-
That's what UIPI is supposed to prevent. If you know a way around it, that's probably a real vulnerability, because you could (for example) do it to the consent dialog..
-
Oops. You're right. Didn't realize UIPI also applies for SendInput too.
Kraj razgovora
Novi razgovor -
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.