New Windows 10 vulnerability allows anyone to get admin privileges - @LawrenceAbrams
bleepingcomputer.com/news/microsoft…
@LawrenceAbrams Security researcher @jonasLyk is the one who discovered that Windows 10 and Windows 11 Registry files associated with the Security Account Manager (SAM) are accessible to users with low privileges.
Mimikatz creator @gentilkiwi told BleepingComputer that anyone can easily steal an elevated account's NTLM hashed password to gain higher privileges by taking advantage of the incorrect file permissions.

vimeo.com/577234015
According to CERT/CC vulnerability analyst @wdormann and SANS author @jeffmcjunkin, Microsoft introduced the permission changes in Windows 10 1809. BleepingComputer has reached out to Microsoft for more info but has not heard back until now.

bleepingcomputer.com/news/microsoft…
@wdormann @jeffmcjunkin This Windows elevation of privilege vulnerability is now tracked by Microsoft as CVE-2021-36934.

Per Microsoft it affects Windows 10 version 1809 and newer client operating systems

msrc.microsoft.com/update-guide/v…

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with BleepingComputer

BleepingComputer Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @BleepinComputer

18 Jul
New Windows print spooler zero day exploitable via remote print servers - @LawrenceAbrams
bleepingcomputer.com/news/microsoft…
@LawrenceAbrams There's a new printer-related zero-day vulnerability that could let hackers gain administrative privileges on vulnerable Windows machines.

It was disclosed publicly by @gentilkiwi and can be exploited through a compromised remote print server
@LawrenceAbrams @gentilkiwi The exploit uses the 'Queue-Specific Files' feature of the Windows Point and Print capability.

Hackers can use it to download and run a malicious DLL with SYSTEM privileges when a client connects to the compromised remote print server
Read 4 tweets
16 Jun
Scammers mail fake Ledger devices to steal your cryptocurrency - @LawrenceAbrams
bleepingcomputer.com/news/cryptocur…
Ledger hardware wallet owners are receiving packages containing what appears to be new Ledger devices in convincing packaging.
The enclosed poorly written letter explains that the device was sent out after the customer's information was posted on the RaidForums hacking forum.
bleepingcomputer.com/news/security/…
Read 9 tweets
16 Jun
Ukraine arrests Clop ransomware gang members, seizes servers - @serghei
bleepingcomputer.com/news/security/…
The National Police of Ukraine says the Clop gang is behind financial damages of $500 million.

Clop's Tor payment and data leak sites are still operational, so it looks like the Clop ransomware operation has not been completely shut down at this time.

If you're curious why Korean police were involved in the investigation:

bleepingcomputer.com/news/security/…
Read 4 tweets
14 May
DarkSide ransomware servers reportedly seized, REvil restricts targets - @LawrenceAbrams
bleepingcomputer.com/news/security/…
As discovered by @ddd1ms, REvil's 'UNKN' posted a message allegedly from DarkSide who claims their servers and cryptocurrency were seized.
Starting yesterday, DarkSide's data leak site became inaccessible leading to thoughts that it was seized by law enforcement.
Read 8 tweets
12 May
Tor Project auctions off the first Onion URL ever created as an NFT - @LawrenceAbrams
bleepingcomputer.com/news/technolog…
Tor is auctioning off the first Onion service ever created known as Dusk.
duskgytldkxiuqc6.onion Image
The winning bid will receive the Onion service's RSA1024 private key as well as one-of-a-kind digital artwork named 'Dreaming of Dusk' created from the key by @IxShellS.
Read 4 tweets
8 Apr
Tech support scammers lure victims with fake antivirus billing emails - @LawrenceAbrams
bleepingcomputer.com/news/security/…
A new tech support scam is targeting people with fake McAfee, Microsoft, and Norton Lifelock billing notices via email, rather then using your typical shady website advertisements.
According to @VadeSecure, they have filtered over 1 million emails so far in this campaign, with it peaking at over 200K emails in a single day.
Read 7 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!

:(