There’s a Severe Privilege Escalation Vulnerability in Windows RPC Protocol That Microsoft Won’t Fix

Discussion in 'other security issues & news' started by guest, Apr 27, 2021.

  1. guest

    guest Guest

    There’s a Severe Privilege Escalation Vulnerability in Windows RPC Protocol That Microsoft Won’t Fix
    April 27, 2021
    https://www.technadu.com/severe-pri...indows-rpc-protocol-microsoft-not-fix/269418/
     
  2. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,542
    Location:
    U.S.A. (South)
    Along with other existing "outside the scope of its responsibility" vulnerabilities already known and yet undiscovered.
    What a champ of a Tech Company.
     
  3. Floyd 57

    Floyd 57 Registered Member

    Joined:
    Mar 17, 2017
    Posts:
    1,296
    Location:
    Europe
    Apparently this has been known for a year?

    https://www.reddit.com/r/netsec/comments/ghpdxn/no_more_juicypotato_old_story_welcome_roguepotato/
    https://www.reddit.com/r/blackhat/comments/ghqv9c/no_more_juicypotato_old_story_welcome_roguepotato/

    11 months.

    https://github.com/antonioCoco/RoguePotato

    The official blog https://decoder.cloud/2020/05/11/no-more-juicypotato-old-story-welcome-roguepotato/ says 11/5, so almost a year.

    I sent an email to 0patch to ask em. Normally they do not respond to free customers, but Im lucky I guess. Will update when they respond
     
  4. Floyd 57

    Floyd 57 Registered Member

    Joined:
    Mar 17, 2017
    Posts:
    1,296
    Location:
    Europe
    upload_2021-4-29_16-53-33.png
    Hmm apparently, they might not have known of this. Or they are still trying to figure it out? Unlikely, been a year now.

    Also he asks me if i'm affected, but as far as I understand, isn't everyoneo_O
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.