{"id":14923,"date":"2010-02-16T07:00:00","date_gmt":"2010-02-16T07:00:00","guid":{"rendered":"https:\/\/blogs.msdn.microsoft.com\/oldnewthing\/2010\/02\/16\/it-rather-involved-being-on-the-other-side-of-this-airtight-hatchway-dubious-escalation\/"},"modified":"2010-02-16T07:00:00","modified_gmt":"2010-02-16T07:00:00","slug":"it-rather-involved-being-on-the-other-side-of-this-airtight-hatchway-dubious-escalation","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/oldnewthing\/20100216-00\/?p=14923","title":{"rendered":"It rather involved being on the other side of this airtight hatchway: Dubious escalation"},"content":{"rendered":"<p>Consider this type of dubious security vulnerability:<\/p>\n<blockquote class=\"q\"><p> There is a buffer overflow bug in kernel driver&nbsp;X. To exploit it, call this function with these strange parameters. The exploit works only if you are logged on as administrator, because non-administrators will get <code>ERROR_ACCESS_DENIED<\/code>. <\/p><\/blockquote>\n<p> Yes, this is a bug, and yes it needs to be fixed, but it&#8217;s not a security bug because of that <i>only if you are logged on as an administrator<\/i> clause.<\/p>\n<p> It&#8217;s another variation of the <a href=\"http:\/\/blogs.msdn.com\/oldnewthing\/archive\/2007\/09\/20\/5002739.aspx\"> dubious elevation to administrator<\/a> vulnerability. After all, if you&#8217;re already an administrator, then why bother attacking kernel mode in this complicated way? Just use your administrator powers to do whatever you want to do directly. You&#8217;re an administrator; you already pwn the machine. All you&#8217;re doing now is flexing your muscles showing how cleverly you can take down a machine that&#8217;s already yours. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Consider this type of dubious security vulnerability: There is a buffer overflow bug in kernel driver&nbsp;X. To exploit it, call this function with these strange parameters. The exploit works only if you are logged on as administrator, because non-administrators will get ERROR_ACCESS_DENIED. Yes, this is a bug, and yes it needs to be fixed, but [&hellip;]<\/p>\n","protected":false},"author":1069,"featured_media":111744,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[26],"class_list":["post-14923","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-oldnewthing","tag-other"],"acf":[],"blog_post_summary":"<p>Consider this type of dubious security vulnerability: There is a buffer overflow bug in kernel driver&nbsp;X. To exploit it, call this function with these strange parameters. The exploit works only if you are logged on as administrator, because non-administrators will get ERROR_ACCESS_DENIED. Yes, this is a bug, and yes it needs to be fixed, but [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/14923","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/users\/1069"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/comments?post=14923"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/14923\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media\/111744"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media?parent=14923"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/categories?post=14923"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/tags?post=14923"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}