ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability

mediumVulnerabilityimportance 50
AI summary · glm-5.3-flash

ZDI disclosed an unpatched local privilege escalation flaw (CVSS 5.3) in Microsoft Windows HTTP Proxy, requiring prior low-privileged code execution.

ZDI-26-708 details a privilege escalation vulnerability in the Microsoft Windows HTTP Proxy component. A local attacker who can already execute low-privileged code on the target system can escalate privileges. ZDI assigned a CVSS rating of 5.3 and published it as a 0day advisory; no CVE id is listed in the bulletin text.

  • Unpatched local privilege escalation in Windows HTTP Proxy
  • Requires existing low-privileged code execution
  • CVSS 5.3, no CVE listed in bulletin
  • Published as ZDI 0day advisory
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3.

This source does not provide full text. Read it at zerodayinitiative.com.