QID 91840
Date Published: 2021-11-24
QID 91840: Microsoft Windows Elevation of Privilege Vulnerability (Zero day)
This vulnerability allows an attacker with a standard (limited) user account to elevate their privileges to become an administrator. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. This vulnerability works in every supporting windows installation. Including November 2021 patch.
Successful Exploit could use discretionary access control list (DACL) for Microsoft Edge Elevation Service (MicrosoftEdgeElevationService) which is a Win32 service to replace any executable file on the system with an MSI file, allowing an attacker to run code as an administrator.
Solution
There are no vendor supplied patches available at this time.
Vendor References
CVEs related to QID 91840
Software Advisories
| Advisory ID | Software | Component | Link |
|---|