Based NightmareEclipse btfoing microslop with endless zero days.He could have sold these all for tens of millions of dollars, instead, he chooses to BTFO Microsoft.>The new bug, dubbed ShieldBreak, is the latest disclosure by security researcher Nightmare Eclipse, who in recent months has published details of several bugs affecting Microsoft’s products, including Windows.>According to Nightmare Eclipse’s post, ShieldBreak takes advantage of a flaw in Windows Defender, the anti-malware and security engine built into Windows. A successful attack allows the hacker to escalate their permissions from a low-level user to full access to the device and its data.
>While it claims to be a RoguePlanet bypass, I'll admit that my naive eyeballs fail to see the similarity.>I've skipped a few minor points, but the general gist is:>1) Set up a temp directory that's registered as a Cloud Sync provider.> Plant an EICAR file> Use Object Manager symlinks to control Defender's scan path to system32.> During the scan, leverage CLFS to swap the identity file and hydration data to C:\Windows\system32\phoneinfo.dll (which doesn't exist by default in Windows)> Run the QueueReporting scheduled task, which runs wermgr.exe -upload as Run with highest privileges>In the wer.dll code, there is explicit code to load phoneinfo.dll. Because at this point, phoneinfo.dll exists and is our own code, this runs, spawning conhost.exe with SYSTEM privileges.
>>109537125m$ftbtfo + reelingwhat about lawsuits?can they even do anything?
>>109537125it is always the funniest when antivirus itself leads to system pwnage.