Closed GoogleCodeExporter closed 9 years ago
Original comment by fors...@google.com
on 17 Oct 2014 at 9:40
Original comment by fors...@google.com
on 28 Nov 2014 at 9:22
Original comment by fors...@google.com
on 2 Dec 2014 at 11:10
Correspondance Date: 29 Oct 2014
> Microsoft say they've reproduced the issue on Windows 7 (8+ is not vulnerable
as expected) and to quote, "it seems to max out as a Medium IL to High IL
elevation which doesn't immediately align with bulletin servicing in that
Medium to High isn't a defined security boundary"
< Responded with informing Microsoft that we don't believe it's a UAC issue
(which is a typical way of describing IL related elevation issues), the use of
the linked token is a PoC implementation issue, it's possible to steal an
administrator level token through other means (such as BITS) while running as a
normal user. The code is clearly incorrectly checking the current impersonation
token for administrator privileges which constitutes a defined security
boundary. Provided a link to a forum post on OSR
(http://www.osronline.com/showthread.cfm?link=201029) where their own Ken
Johnson provides caution for this exact security issue. That said it's conceded
that there's no obvious serious security implication associated with the bypass
of the check.
Original comment by fors...@google.com
on 13 Jan 2015 at 12:32
Correspondance Date: 14 Jan 2015
< Asked Microsoft if they believe this issue is not going to be fixed and if so
whether we can make it as won't fix and remove the view restriction.
Original comment by fors...@google.com
on 14 Jan 2015 at 9:44
Correspondance Date: 14 Jan 2015
> Microsoft have stated that this issue is not considered serious enough for a
bulletin release as it only allows limited information disclosure about power
settings. It will be under consideration for fixing in future versions of
Windows.
We agree with this assessment and will remove the view restriction on the issue.
Original comment by fors...@google.com
on 15 Jan 2015 at 8:48
[deleted comment]
Rebase_all_Google_Microsoft_gmail_github
Original comment by HONEST11...@gmail.com
on 27 Feb 2015 at 7:26
Correspondence Date: 10 Mar 2015
< Asked Microsoft if CVE-2015-0075 in MS15-025 fixed SeTokenIsAdmin downlevel
as that would make this issue fixed.
Original comment by fors...@google.com
on 12 Mar 2015 at 3:46
Original issue reported on code.google.com by
fors...@google.com
on 17 Oct 2014 at 10:22Attachments: