Security News > 2020 > November > Games in Microsoft Store Can Be Abused for Privilege Escalation on Windows

Games in Microsoft Store Can Be Abused for Privilege Escalation on Windows
2020-11-04 13:37

A researcher at cybersecurity services provider IOActive has identified a privilege escalation vulnerability in Windows that can be exploited by abusing games in the Microsoft Store.

Ferrante discovered the vulnerability after Microsoft announced that it started allowing mods for some games in the Microsoft Store.

Ferrante created symlinks between the ModifiableWindowsApps folder, which Microsoft created for storing games that can be moded, and a folder placed on a different drive that he could access.

The attack requires the attacker to change Windows storage settings so that new apps are saved to the drive they have access to, and they also need to install a game from the Microsoft Store.

The attack scenario described by Ferrante involves steps that would be visible on the screen, such as installing a game from the Microsoft Store and changing storage settings, which would increase the chances of the victim discovering the attack.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/oVvhl6atFTg/games-microsoft-store-can-be-abused-privilege-escalation-windows

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 382 52 1419 2916 176 4563