sportsboy / google-security-research

Automatically exported from code.google.com/p/google-security-research
0 stars 0 forks source link

Windows: Creating Hardlinks Doesn't Require Write Permissions to the Target #531

Closed GoogleCodeExporter closed 8 years ago

GoogleCodeExporter commented 8 years ago
Microsoft requested I removed information from a public presentation that you 
can create NTFS hardlinks without needing write permissions on the target file. 
Their view is they want to fix this, at the least to prevent its abuse in 
sandboxed applications so a case has been set up to track the issue. It's still 
under the normal 90 day SLA.

This bug is subject to a 90 day disclosure deadline. If 90 days elapse
without a broadly available patch, then the bug report will automatically
become visible to the public.

Original issue reported on code.google.com by fors...@google.com on 14 Sep 2015 at 11:01

GoogleCodeExporter commented 8 years ago
Microsoft have confirmed they've reproduced the issue.

Original comment by fors...@google.com on 18 Sep 2015 at 10:44

GoogleCodeExporter commented 8 years ago
Fixed in MS15-115 
https://technet.microsoft.com/en-us/library/security/MS15-115. Microsoft have 
removed the ability to use this trick from sandboxed processes.

Original comment by fors...@google.com on 17 Nov 2015 at 11:22