Skip to main content

Microsoft (Belatedly) Admits to Windows Server 2008 Token Kidnapping

posted onApril 20, 2008
by hitbsecnews

Last month, when I wrote about hacker Cesar Cerrudo's (left) plans to punch holes in the security model of Microsoft's brand-new Windows Server 2008, Redmond officials pinged me to stress that his presentation "describes design issues and does not describe a new vulnerability."

Imagine my surprise this morning to see this Microsoft pre-patch security advisory confirming "new public reports of a vulnerability which could allow elevation of privilege from authenticated user to LocalSystem" on Windows XP SP2 and all supported versions and editions of Windows Server 2003, Windows Vista and Windows Server 2008.

The language from Cerrudo's talk -- which was presented at the Hack in the Box conference this week -- and Microsoft's advisory sounded very much the same, so I contacted Microsoft again to verify that it's indeed the same issue.L33tdawg (Edited 22nd April): Presentation materials from the conference including Cesar's slides have been released on the conference page. Official photos from the event will be out this week as well...

Source

Tags

Microsoft

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th