Google Project Zero researcher James Forshaw details a complex vulnerability he discovered in Windows 11's new Administrator Protection feature, which aims to replace UAC with a more secure privilege elevation system. The bypass exploits a chain of five OS behaviors involving logon sessions, DOS device object directories, and

23m read timeFrom projectzero.google
Post cover image
Table of contents
The Problem Administration Protection is Trying to SolveResearching Administrator ProtectionLogon SessionsCreating a DOS Device Object DirectoryBypassing Administrator ProtectionFinal Thoughts

Sort: