A Google security researcher, James Forshaw, has uncovered a significant privilege escalation vulnerability in Windows 8.1, which poses a serious threat to users by allowing potential intruders to manipulate system content or completely seize control of affected machines. This new flaw puts millions at risk by potentially circumventing existing security protocols and allowing unauthorized access.
The researcher has supplied a Proof of Concept (PoC) for this vulnerability, affirming that his tests were limited to an updated version of Windows 8.1, raising questions about the susceptibility of earlier iterations, particularly Windows 7. Forshaw initially identified the issue in September 2014 and brought it to the attention of the Google Security Research mailing list at the end of the month. After the standard 90-day disclosure period, he made both the vulnerability and the PoC widely accessible on Wednesday.
This vulnerability stems from an internal function known as AhcVerifyAdminContext, which checks whether a user has administrative privileges. Forshaw detailed the issue, explaining that the function fails to accurately verify the impersonation token of the requesting user, allowing an attacker to bypass expected checks by exploiting the token reading mechanism. The PoC takes advantage of this flaw using the BITS service and COM, though there may be other potential methods to exploit the vulnerability.
The PoC provided includes two executable files along with instructions for successfully executing the files. If the procedure is done correctly, it allows the Windows calculator to launch with administrative rights. Forshaw clarified that the issue is not rooted in Windows User Account Control (UAC) but rather demonstrates the vulnerability’s implications through its interaction with UAC.
Verification of the PoC requires that users set up the application files correctly, ensuring UAC is active, and providing the appropriate environment for execution. Forshaw’s testing included both 32 and 64-bit versions of Windows 8.1, with a recommendation to utilize the 32-bit version for the PoC exercise.
Microsoft has acknowledged the weakness and is reportedly working on a patch. A spokesperson emphasized that for an attacker to exploit this flaw, they would require valid credentials and local access to the target machine. They stressed the importance of keeping antivirus software current, applying all available security updates, and enabling firewall protections.
As of the time of this report, there is no available patch, leaving all Windows 8.1 systems exposed to potential exploitation. Business owners and IT professionals should remain vigilant, heartening their users to practice safe computing habits until an official fix is released. Understanding the MITRE ATT&CK framework may help identify the adversary tactics relevant to this vulnerability, particularly regarding privilege escalation and potential initial access to systems that could lead to greater security breaches.