Windows 0-day vulnerability bypasses UAC

Winrumors has reported that a new 0-day vulnerability affecting Windows XP, Vista and 7 has been discovered. The vulnerability resides in win32k.sys, “the kernel mode part of the Windows subsystem.” This exploit allows user priviledge elevation, enabling even limited accounts to execute arbitrary code.

Marco Giuliani of Prevx has stated that…



Neowin.net