Windows证书对话框权限提升漏洞(CVE_2019-1388) CVE_2019-1388

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

This vulnerability is a truly delicious one, and credit for it goes to ZDI contributor Eduardo Braun Prado. Your guests won’t believe how easy it is to escalate to SYSTEM! The bug is found in the UAC (User Account Control) mechanism. By default, Windows shows all UAC prompts on a separate desktop known as the Secure Desktop. The prompts themselves are produced by an executable named `consent.exe`, running as `NT AUTHORITY\SYSTEM` and having an integrity level of System. Since the user can interact with this UI, it is necessary for the UI to be very tightly constrained. Otherwise, a low privileged user might be able to perform actions as SYSTEM via a circuitous route of UI operations. Even a solitary UI feature that appears harmless in isolation could potentially be the first step in a chain of actions leading to arbitrary control. Indeed, you will find that the UAC dialogs are stripped down to contain a bare minimum of clickable options. Shall we go exploring a bit? We can enter...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息