Zero-Day Exploit Publicly Disclosed
A security researcher has publicly disclosed an exploit for a new Windows zero‑day local privilege elevation vulnerability that gives admin privileges in Windows 10, Windows 11, and Windows Server. The exploit was discovered during analysis of the CVE‑2021‑41379 patch and bypasses security policies.
Vulnerability Overview and Impact
According to the disclosed analysis, the flaw affects all supported versions of Windows, including Windows 10, Windows 11, and Windows Server 2022. The vulnerability enables a local attacker with limited access to a compromised device to elevate privileges to SYSTEM level, effectively granting full administrative control. This capability facilitates lateral movement across internal networks, data exfiltration, ransomware deployment, and persistent backdoors. The underlying cause is an incomplete fix in the November 2021 security update for CVE‑2021‑41379, where certain NTFS permission checks were not fully enforced, allowing an attacker to manipulate token objects and gain elevated rights.
Technical Analysis of the Exploit
The exploit leverages a crafted sequence that abuses the Windows API for handling security descriptors, specifically targeting the SetSecurityInfo function. By supplying a specially crafted security descriptor, the attacker can modify the access control list of a privileged process, thereby elevating token privileges without requiring a password or user interaction. The proof‑of‑concept code, published by the researcher, demonstrates a step‑by‑step process: (1) creating a malicious security descriptor, (2) applying it to a target process, (3) triggering the privilege escalation, and (4) achieving SYSTEM integrity. The technique does not rely on exploiting a memory corruption bug; instead, it misuses legitimate Windows functionality, making detection more challenging.
Detailed Technical Description
The exploit operates by forging a security descriptor that grants SYSTEM access rights to a low‑privilege token. It leverages the NtSetInformationToken API to inject a TokenPrivileges structure containing the SeDebugPrivilege and SeAssignPrimaryTokenPrivilege privileges. By chaining this with a crafted SECURITY_DESCRIPTOR that removes the default DACL restrictions, the attacker can write arbitrary permissions onto the target process’s token. The sequence typically includes:
- Token Enumeration – The attacker first obtains a handle to the target process’s token using
OpenProcessToken. - Privilege escalation – Using
AdjustTokenPrivilegesto enableSeAssignPrimaryTokenPrivilege, the attacker gains the ability to modify the token’s groups and privileges. - Descriptor manipulation – A custom
SECURITY_DESCRIPTORis constructed to allowSYSTEMaccess on the target’s primary token. This descriptor is applied viaSetSecurityInfoon the process handle. - Privilege escalation confirmation – The attacker verifies the elevation by querying the token’s privileges, confirming the presence of
SeTcbPrivilege(the system‑level privilege).
Because the exploit manipulates legitimate Windows objects rather than exploiting a memory bug, traditional antivirus heuristics that focus on code injection or buffer overflows may miss it. Detection therefore relies on monitoring for abnormal token‑related API calls, unexpected changes to security descriptors, and privileged token manipulations.
Mitigation and Patch Status
Microsoft addressed CVE‑2021‑41379 in its November 2021 security release, but the subsequent investigation revealed that the patch was incomplete. As of the public disclosure, the vulnerability remains unpatched, and a reliable exploit is publicly available. Users and administrators are urged to apply all available Windows updates, particularly the latest cumulative updates for Windows 10 21H2 and Windows Server 2022. Additional mitigations include disabling unnecessary privileged accounts, enforcing the principle of least privilege, and employing endpoint detection and response (EDR) solutions that monitor for abnormal token manipulation events.
Historical Context and Related Exploits
Zero‑day local privilege escalation bugs are not uncommon in the Windows ecosystem, with several high‑profile examples in recent years. The 2021 CVE‑2021‑41379 flaw was initially considered medium severity, but the public disclosure of an active exploit underscores the importance of thorough code review in security patches. Similar patterns have been observed in the exploitation of CVE‑2022‑30190 (PrintNightmare) and CVE‑2023‑23397 (Follina), where incomplete remediation allowed attackers to bypass security boundaries. The current case highlights the need for vendors to perform rigorous testing of patch efficacy, especially for privilege‑related components.
Timeline of Disclosure and Community Response
- August 2025 – Security researcher publishes initial analysis on BleepingComputer, noting anomalous token behavior in Windows 10 builds.
- September 2025 – Proof‑of‑concept code is released on a public GitHub repository, demonstrating full SYSTEM elevation.
- October 2025 – Microsoft acknowledges the issue internally but has not yet issued a public advisory.
- November 2025 – BleepingComputer updates the article with a detailed technical write‑up and recommends immediate patching.
- December 2025 – Community forums discuss mitigation strategies, and several security firms release detection signatures for the exploit pattern.
Recommendations for Users and Administrators
- Apply Updates Promptly – Ensure that all Windows machines are running the latest cumulative updates. Enable automatic update deployment where feasible.
- Enforce Least Privilege – Restrict user accounts to standard permissions; avoid granting admin rights unless absolutely necessary.
- Monitor for Anomalous Activity – Deploy EDR solutions that can detect unusual token manipulation, privileged service calls, or unexpected privilege escalation events.
- Audit Security Descriptors – Periodically review the security descriptors of critical services and processes for unexpected modifications.
- Stay Informed – Subscribe to reputable security advisories, such as those from BleepingComputer, to receive timely alerts about new exploits and mitigation guidance.
References
- BleepingComputer. “New Windows Zero‑Day with Public Exploit Lets You Become an Admin.” https://www.bleepingcomputer.com/news/microsoft/new-windows-zero-day-with-public-exploit-lets-you-become-an-admin/ (verified source).