Exploiting Design Flaws in the Win32 API for Privilege Escalation

This paper presents a new generation of attacks against Microsoft Windows, and possibly other message-based windowing systems. The flaws presented in this paper are, at the time of writing, unfixable. The only reliable solution to these attacks requires functionality that is not present in Windows, as well as efforts on the part of every single Windows software vendor.” Read the paper over at Tombom.co.uk. In the meantime, another flaw affects Windows 2000, Linux and MacOSX.

13 Comments

  1. 2002-08-07 6:03 pm
  2. 2002-08-07 6:26 pm
  3. 2002-08-07 6:32 pm
  4. 2002-08-07 7:14 pm
  5. 2002-08-07 7:25 pm
  6. 2002-08-07 7:36 pm
  7. 2002-08-07 7:51 pm
  8. 2002-08-07 8:18 pm
  9. 2002-08-08 7:59 am
  10. 2002-08-08 11:56 am
  11. 2002-08-08 11:57 am
  12. 2002-08-08 3:47 pm
  13. 2002-08-09 12:53 am