New blog post: "CDPSvc DLL Hijacking - From LOCAL SERVICE to SYSTEM" where I mostly talk about Tokens and Impersonation.
https://itm4n.github.io/cdpsvc-dll-hijacking/ …pic.twitter.com/pqi7k2thcS
You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more
Why they fixed the one in 8.1 I cannot answer. Maybe it was before they realized that the battle was unwinnable?
If MS knows that a user-writable system PATH makes for an exploitable OS, then maybe their OS should tell users whenever that's the case? 
Actually, where do you see a reference of Microsoft fixing the IKEEXT service? (CVE) Closest I can find is https://www.immuniweb.com/advisory/HTB23108 … which lists CVEs for each app that has an unprotected dir in the system PATH. Which mirrors what I described. Its unprotected dirs that's the prob.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.