Technical Advisory: SeriousSAM – Windows 10 Flaw Can Be Used by Malicious Actors to Obtain Administrator Rights

Technical Advisory: SeriousSAM – Windows 10 Flaw Can Be Used by Malicious Actors to Obtain Administrator Rights

Newer versions of Windows 10 (build 1809 - 2018-present) may be vulnerable to a local privilege escalation enabled by misconfiguration on the Security Account Manager (SAM) database file. SAM is a database file that stores password hashes for all local user accounts. (This file can be found in folder %SystemRoot%\System32\Config\SAM and it is mounted in registry under HLKM\SAM.)

Article Link: http://feedproxy.google.com/~r/BusinessInsightsInVirtualizationAndCloudSecurity/~3/482PRmecwSU/technical-advisory-serioussam-windows-10-flaw-can-be-used-by-malicious-actors-to-obtain-administrator-rights