Here's a promised write-up of Windows Privilege Elevation bug that I've discovered / CVE-2021-26415
https://www.cloaked.pl/2021/04/cve-2021-26415/ …
#security #EOP #LPE #bugbountypic.twitter.com/VJzEcXw4tu
-
-
Replying to @a_denkiewicz @404death
Jonas L Retweeted Jonas L
suggestions: can you inject delete character to gain more control over data? tried: edges updater? opens ini in root`? tried win.ini ? https://twitter.com/jonasLyk/status/1374961171342708736 … that trick can send all impersonating file opens one way- not, another
Jonas L added,
2 replies 0 retweets 4 likes -
So is this another way of tricking a file open from anywhere on the system to somewhere you can control by redirecting the Global object back to RPC Control? Then creating another symlink to somewhere else?
1 reply 0 retweets 0 likes
instead of seperatng by open count- i seperate by identity
4:14 AM - 22 Apr 2021
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.