Bypass Windows user interface privilege isolation via the CTF input method proto
projectzero.google·1d·
Discuss: Hacker News
🔓Binary Exploitation
Preview
Report Post

Posted by Tavis Ormandy, Security Research Over-Engineer.

“Sometimes, hacking is just someone spending more time on something than anyone else might reasonably expect.”[1]

I often find it valuable to write simple test cases confirming things work the way I think they do. Sometimes I can’t explain the results, and getting to the bottom of those discrepancies can reveal new research opportunities. This is the story of one of those discrepancies; and the security rabbit-hole it led me down.

It all seemed so clear..

Usually, windows on the same desktop can communicate with each other. They can ask each other to move, resize, close or even send each other input. This can get complicated when you have applications with different privilege levels, for example, if y…

Similar Posts

Loading similar posts...