newsbot
03-09-2010, 03:00 PM
A prominent researcher will use an upcoming security conference in Buenos Aires to demonstrate an exploit that allows hackers to bypass the Windows Service Isolation feature, despite Microsoft's efforts to close the security loophole.Security researcher Cesar Cerrudo of Argeniss Information Security and Software said he will demonstrate an exploit he has developed that would allow hackers to bypass a security feature called Windows Service Isolation, which is intended to make it easier to access Windows objects without requiring a administrator level privileges. Cerrudo will use the upcoming ekoparty Security Conference in Buenos Aires to present his exploit. Writing to Threatpost.com, Cerrudo said that his presentation will demonstrate a method to bypass the Windows Service Isolation feature, allowing an attacker who is able to upload content to a Windows endpoint running applications such as SQL server and Internet Information Server (IIS) to elevate her privileges from the limited Local Service or Network Service account to the Local System account, providing broad access to install malicious code on or otherwise modify the system.
**Hidden Content: Check the thread to see hidden data.**
**Hidden Content: Check the thread to see hidden data.**