4 ms·
Some of these attacks are remote, some are local privilege escalation flaws. The local attacker should have user-level access, but instead has admin/system-lev
by mryan 11y ago
Some of these attacks are remote, some are local privilege escalation flaws.
The local attacker should have user-level access, but instead has admin/system-level access.
- higherpurpose 11y agoResearchers seem to encounter a handful of privilege escalation vulnerabilities for Windows every year. I wonder if this will ever be "fixed" (dramatically reduced in number). A well organized cyber-crime group or a whole number of spy agencies could have access to at least one such vulnerability throughout the year.
- zamalek 11y agoThis specific case is not Windows. It's Lenovo's unbelievable hostility toward their customers in combination with their amazingly aptitude for being completely incompetent. I would venture to guess that the adware service is running as SYSTEM. Any vulnerability in the service would escalate to system. You can do exactly the same thing in Linux (daemon running as root) and it would have a very similar surface area. The only difference in this specific case is that Windows has idiots for hardware manufacturers. The only way to "fix" it would be for Microsoft to encourage users to wipe the default installation.