Windows 10: PoC for Windows VCF zero-day published online

Discus and support PoC for Windows VCF zero-day published online in Windows 10 News to solve the problem; A security researcher has published details and proof-of-concept (PoC) code for an unpatched Windows vulnerability that affects the way Windows handles... Discussion in 'Windows 10 News' started by Brink, Jan 15, 2019.

  1. Brink Win User

    PoC for Windows VCF zero-day published online


    Read more: PoC for Windows VCF zero-day published online | ZDNet

    :)
     
    Brink, Jan 15, 2019
    #1

  2. 6680 PoC or PTT

    Does your network operator support PoC?

    Do you have the correct PoC settings in the phone?
     
    embedded_system, Jan 15, 2019
    #2
  3. P4-630 Win User
    Windows Zero-Day Flaw Goes on Sale for $90,000

    A Windows zero-day vulnerability that gives hackers system privileges to compromised devices is being sold for US$90,000. (Works on ALL Windows Versions)

    PoC for Windows VCF zero-day published online Windows-10-Security.jpg

    For $90,000, Windows zero day flaw could be yours
    A Windows zero day flaw that reportedly works against all versions of Windows from Windows 2000 to the latest Windows 10, is up for sale for $90,000. The local privilege escalation (LPE) vulnerability is being sold on a Russian cybercrime forum exploit.in and claims to help attackers who already have access to target machines. The vulnerability, thus, can be used along with other vulnerabilities to successfully run malware code and get admin access on the victim devices running Windows operating system.

    The seller known as BuggiCorp on the forum has published two proof-of-concept videos of an exploit that makes use of this zero-day vulnerability. One of these videos demonstrates the exploit being successfully used with Microsoft’s popular EMET (Mitigation Toolkit) running on the target machine. Enhanced Mitigation Experience Toolkit brings a number of security features to the Windows operating system, working against both known and unknown Windows vulnerabilities, and third-party applications running on the OS.


    The vulnerability, as shown in the PoC videos show the exploit working on a Windows 10 machine, and elevating cmd.exe process to system level privilege account, essentially giving a hacker admin rights. Researchers have said that having access to an employee’s account, a hacker could turn an unprivileged account to an admin account with god-mode rights.


    Security researchers from Trustwave’s SpiderLabs team have done an extensive post on this claimed vulnerability, and the team says the “seller has put in the effort to present himself/herself as a trustworthy seller with a valid offering.”

    One of the main indicators for this is the fact that the seller insists on conducting the deal using the forum’s admin as the escrow.

    […] A quick thought about the price of this zero day. We don’t have many public records of what the price of such exploit should be… the price here seems on the high end but still within a realistic price range, especially considering the return on investment criminals are likely to make using this exploit in any campaign.

    SpiderLabs also says that it’s comparatively rare to see such zero-day flaws being offered for sale in the open. “Zero days have long been sold in the shadows. In this business you usually need to “know people who know people” in order to buy or sell this kind of commodity,” the team noted.

    Microsoft will be a likely buyer of this zero-day flaw as the company spends more than $90,000 to find out about such critical flaws. The Windows zero day flaw went on sale on “Patch Tuesday,” making sure that the exploit will work for longer time, until Microsoft releases a fix.


    PoC for Windows VCF zero-day published online windows-zero-day-flaw.png


    http://wccftech.com/windows-zero-day-flaw-goes-on-sale-for-90000/
     
    P4-630, Jan 15, 2019
    #3
  4. PoC for Windows VCF zero-day published online

    How do I unblock a publisher in windows 10?

    I have gone through the steps as suggested above BUT interestingly don't see an publisher listed under the "Untrusted Publishers" but still get the same error box as shared above.

    Screenshot

    I wonder why?
     
    Tanveer Malik, Jan 15, 2019
    #4
Thema:

PoC for Windows VCF zero-day published online

Loading...
  1. PoC for Windows VCF zero-day published online - Similar Threads - PoC VCF zero

  2. 'Zero Day' 'Nitro Zeus'

    in AntiVirus, Firewalls and System Security
    'Zero Day' 'Nitro Zeus': How do you know if your device has been infected. https://answers.microsoft.com/en-us/protect/forum/all/zero-day-nitro-zeus/cac08d82-bc0f-4707-9779-f4cce2703b00
  3. Day zero OS updates

    in Windows 10 Installation and Upgrade
    Day zero OS updates: I recently bought a HP Pavilion laptop, which was advertised as complete with all the necessary windows win10 home version updates, yet I have been battling seemingly endless day 0 updates since I got it. Most notably, a feature update to version 1909 which for some reason...
  4. VCF files

    in Windows 10 Network and Sharing
    VCF files: I am looking for a simple way to combine several VCF files saved on PC so that I can edit them and export to an old flip phone https://answers.microsoft.com/en-us/windows/forum/all/vcf-files/ea992044-cbda-448b-a0f9-637d8ce3beec"
  5. Windows 10 zero-day exploit code released online

    in Windows 10 News
    Windows 10 zero-day exploit code released online: A security researcher has published today demo exploit code on GitHub for a Windows 10 zero-day vulnerability. The zero-day is what security researchers call a local privilege escalation (LPE). LPE vulnerabilities can't be used to break into systems, but hackers can use...
  6. Microsoft Exchange vulnerable to PrivExchange zero-day

    in Windows 10 News
    Microsoft Exchange vulnerable to PrivExchange zero-day: Microsoft Exchange 2013 and newer are vulnerable to a zero-day named "PrivExchange" that allows a remote attacker with just the credentials of a single lowly Exchange mailbox user to gain Domain Controller admin privileges with the help of a simple Python tool. Details about...
  7. Temporary micropatch available for zero-day Windows exploit

    in Windows 10 Updates and Activation
    Temporary micropatch available for zero-day Windows exploit: "A publicly disclosed Windows zero-day vulnerability could allow attackers to take full control of systems once they compromise a low-privilege account. Here's a fix." Source: Temporary micropatch available for zero-day Windows exploit 125676
  8. Convert Contacts file to .VCF

    in Windows 10 Support
    Convert Contacts file to .VCF: Windows 10 has a routine to make this conversion but it does not appear to work. With thanks to Claesoc's post on 5 November 2013 *sarc[/i] then 2. Import csv 3. Export to vcf 4. Enjoy This same routine comes up in Windows 10 but it doesn't work for me and Outlook...
  9. Internet Explorer zero-day alert

    in Windows 10 News
    Internet Explorer zero-day alert: Scary stuff! Thanks for the tip...
  10. New Flash Player Zero-Day in The Wild

    in Windows 10 News
    New Flash Player Zero-Day in The Wild: A new flaw in latest version of Flash to be patched next week. On my systems I use the free version of Malwarebytes Anti-Exploit to protect my systems. I guess we will see another updated from MS also. https://blog.malwarebytes.org/zero-d..._medium=social Jim *Cool...

Users found this page by searching for:

  1. $90 000 zero-day exploit for sale: It could potentially impact all Windows OS versions