{"id":140110,"date":"2019-05-28T20:56:17","date_gmt":"2019-05-28T20:56:17","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=140110"},"modified":"2025-07-01T21:53:06","modified_gmt":"2025-07-02T04:53:06","slug":"windows-10-new-vulnerability-found","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/windows-10-new-vulnerability-found\/","title":{"rendered":"Windows 10: New vulnerability found"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-140121\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/05\/Windows_10_warning_msdc1y.jpg\" alt=\"Warning Windows 10\" width=\"700\" height=\"394\"><\/p>\n<p>Zero-day vulnerabilities are potential security weak points found in programs after they\u2019ve been released. Obviously, the program developers are unaware of the vulnerabilities, so it is often third parties who discover them and then share their findings so that they can be closed up by the developers in question. We\u2019ve reported a couple of times on <a href=\"https:\/\/en.softonic.com\/articles\/google-has-found-a-security-flaw-in-microsofts-new-operating-system\" target=\"_blank\" rel=\"noopener noreferrer\">Google\u2019s dedicated zero-day hunting team and the bugs they\u2019ve found<\/a>.<\/p>\n<h2>A new zero-day vulnerability has been discovered in Windows 10 that could lead to a malicious attack<\/h2>\n<p>According to a report by <a href=\"https:\/\/www.zdnet.com\/article\/windows-10-zero-day-exploit-code-released-online\/\" target=\"_blank\" rel=\"noopener noreferrer\">ZDNet<\/a>, the new vulnerability was discovered by security researcher SandboxEscaper. The vulnerability relates to Windows Task Scheduler but is unable to take control of a victim\u2019s computer alone. However, if it is used in conjunction with other nefarious methods it could prove very harmful to the victim\u2019s online security. When done so, the vulnerability allows the hacker to run a specific .job file within Task Scheduler to <strong>grant admin privileges.<\/strong><\/p>\n<figure id=\"attachment_140119\" aria-describedby=\"caption-attachment-140119\" style=\"width: 700px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-140119\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2021\/05\/windows_10_zero_day_screenshot_f66woy.jpg\" alt=\"zero day windows 10 screenshot\" width=\"700\" height=\"298\"><figcaption id=\"caption-attachment-140119\" class=\"wp-caption-text\">Image via: <a href=\"https:\/\/www.zdnet.com\/article\/windows-10-zero-day-exploit-code-released-online\/\" target=\"_blank\" rel=\"noopener noreferrer\">ZDNet<\/a><\/figcaption><\/figure>\n<p>SandboxEscaper&nbsp;<a href=\"https:\/\/web.archive.org\/web\/20190522011933\/https:\/\/github.com\/SandboxEscaper\/polarbearrepo\/tree\/master\/bearlpe\" target=\"_blank\" rel=\"noopener noreferrer\">published the details and code of the vulnerability to GitHub<\/a>, without notifying Microsoft. This means there is still no official word on when a patch for the exploit will be available. As to whether it is responsible behavior to publish a vulnerability, including code and demonstration video, online without first notifying the developers that could close it off is for you to decide. <strong>Hackers now know of this vulnerability and we now have to wait for Microsoft to patch it.<\/strong><\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\">\n<p dir=\"ltr\" lang=\"en\">Researcher also released a demo video of the LPE zero-day in action. See below: <a href=\"https:\/\/t.co\/ZX8XWLQ74z\">pic.twitter.com\/ZX8XWLQ74z<\/a><\/p>\n<p>\u2014 Catalin Cimpanu (@campuscodi) <a href=\"https:\/\/twitter.com\/campuscodi\/status\/1131008346197307394?ref_src=twsrc%5Etfw\">May 22, 2019<\/a><\/p><\/blockquote>\n<p>This isn\u2019t the first time SandboxEscaper has acted in this way either. According to the same ZDNet report, she released four other Windows zero-day vulnerabilities in the same manner last year. Three of these were patched by Microsoft without any problems but one of them was used in active malware campaigns for weeks after its release.<\/p>\n<p>It took Microsoft between one or two months to patch the four vulnerabilities SandboxEscaper published in 2018 which means there will be a lot of pressure at Microsoft HQ, if the software giant wants to fix this latest vulnerability in time for its next scheduled patch on Tuesday, June 11. Microsoft has two weeks if it wants to hit that deadline.<\/p>\n<div class=\"sc-related-articles-white\">\r\n<p class=\"sc-related-articles-white__title\">Read more<\/p>\r\n  <div class=\"sc-related-articles-white__row\">\r\n    <a title=\"New scam spotted on the Google Play Store \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/google-play-store-scam-app\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/08\/google-play-192.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>New scam spotted on the Google Play Store \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n    <a title=\"Security alert: new Netflix phishing scams \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/security-alert-new-netflix-phishing-scams\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2019\/02\/netflix-logo-192.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>Security alert: new Netflix phishing scams \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n  <\/div>\r\n  <div class=\"sc-related-articles-white__row\">\r\n    <a title=\"This ingenious phishing scam is targeting iPhone users \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/iphone-phishing\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/10\/iphone-192.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>This ingenious phishing scam is targeting iPhone users \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n    <a title=\"New year, new scams: what to watch out for in 2019 \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/online-scams-in-2019\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/12\/phishing-scam-hacker-malware-192.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>New year, new scams: what to watch out for in 2019 \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n  <\/div>\r\n<\/div>\n<p>So, who exactly is vulnerable to this potential exploit? It has only been confirmed so far on Windows 10 32-bit systems but it is believed, however, that, in theory at least, <strong>it could be adapted to work on all Windows systems<\/strong> all the way back to Windows XP and Server 2003.<\/p>\n<p>When a hacker gains administrative privileges over a system it gives them <strong>complete access<\/strong> to everything on it. This potential vulnerability should be taken seriously, but all we can do for now is hope that Microsoft gets a patch out before hackers start trying to exploit it.<\/p>\n<div class=\"sc-related-articles-white\">\r\n<p class=\"sc-related-articles-white__title\">More about Windows 10<\/p>\r\n  <div class=\"sc-related-articles-white__row\">\r\n    <a title=\"How to start Windows 10 in safe mode \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/windows-10-safe-mode\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/01\/windows-10-192.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>How to start Windows 10 in safe mode \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n    <a title=\"How to turn on Bluetooth in Windows 10 \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/bluetooth-windows-10\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2019\/02\/bluetooth-192.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>How to turn on Bluetooth in Windows 10 \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n  <\/div>\r\n  <div class=\"sc-related-articles-white__row\">\r\n    <a title=\"Windows 10 has a new free Microsoft Office app \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/windows-10-new-free-microsoft-office-app\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2017\/12\/office-192.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>Windows 10 has a new free Microsoft Office app \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n    <a title=\"Microsoft\u2019s latest trick to get you to upgrade to Windows 10 \u25ba\" href=\"https:\/\/en.softonic.com\/articles\/windows-media-player-metadata\">\r\n    <div class=\"sc-related-articles-white__article\">\r\n      <div class=\"sc-related-articles-white__image\">\r\n        <div style=\"background-image:url(https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2018\/09\/windows10-circle-192.jpg)\"><\/div>\r\n      <\/div>\r\n      <div class=\"sc-related-articles-white__text\">\r\n        <p>Microsoft\u2019s latest trick to get you to upgrade to Windows 10 \u25ba<\/p>\r\n      <\/div>\r\n    <\/div>\r\n    <\/a>\r\n  <\/div>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A new zero-day vulnerability has been discovered in Windows 10 that could lead to a malicious attack.<\/p>\n","protected":false},"author":9073,"featured_media":140122,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[2351,1027,1080,1052],"usertag":[839],"vertical":[],"content-category":[],"class_list":["post-140110","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectionwindows-10","tag-security","tag-windows","tag-windows-10","usertag-vpn"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/140110","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9073"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=140110"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/140110\/revisions"}],"predecessor-version":[{"id":325971,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/140110\/revisions\/325971"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/140122"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=140110"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=140110"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=140110"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=140110"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=140110"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=140110"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}