SandboxEscaper female hacker has exposed four Windows 10 zero-day vulnerabilities

Security researchers released two days ago called SandboxEscaper some zero-day vulnerability for Windows 10 system, and promised to follow-up will open more Windows 10 zero-day vulnerabilities. Security researchers yesterday the name promises, they released four zero-day vulnerabilities, fortunately, is one of the vulnerabilities have been fixed in this month's Patch Tuesday Japan-China activities.

SandboxEscaper female hacker has exposed four Windows 10 zero-day vulnerabilities 

According to her blog content, she wants to sell her vulnerability to those found in "hate America" ​​and, apparently retaliation FBI issued a subpoena to her Google account. GitHub proof of concept (proof-of-concepts) contains three Windows local privilege escalation (LPE) security vulnerabilities, as well as a sandbox in IE 11 browser vulnerabilities to escape. But one of the LPE vulnerabilities have been fixed in this month patch Tuesday activities.

Zero-day vulnerabilities in paragraph 3 has not been restored in the most serious is the number for the CVE-2019-0863 vulnerability is LPE vulnerability for Windows Error Reporting service, the severity of the CVSS 3.0 score of 7.8 points (high).

Guess you like

Origin www.linuxidc.com/Linux/2019-05/158831.htm