In a recent PoC Exploit released via YouTube, Alexander Korznikov demonstrated a successful hijacking (using Task manager, service creation, as well as command line), along with Proof-of-Concept exploit.
Korznikov, an Israeli security researcher calls the attack “privilege escalation and session hijacking,” which could allow an attacker to hijack high-privileged users session and gain unauthorized access to applications and other sensitive data.
Korznikov successfully tested the flaw on the newest Windows 10, Windows 7, Windows Server 2008, and Windows Server 2012 R2, though another researcher confirmed on twitter that the flaw works on every Windows version, even if the workstation is locked.
For successful exploitation, an attacker requires physical access to the targeted machine, but using (RDP) Remote Desktop Protocol session on a hacked machine, the attack can be performed remotely as well.
While Microsoft doesn’t believe this to be a vulnerability, some experts argue that a Windows user with admin permissions can do anything, Korznikov explained a simple attack scenario of how an insider could easily misuse this flaw.
“Some bank employee have access to the billing system and its credentials to log in. One day, he comes to work, logging into the billing system and start to work. At lunchtime, he locks his workstation and goes out for lunch. Meanwhile, the system administrator can use this exploit to access employee’s workstation.”
“According to the bank’s policy, administrator’s account should not have access to the billing system, but with a couple of built-in commands in windows, this system administrator will hijack employee’s desktop which he left locked. From now, a sysadmin can perform malicious actions in billing system as billing employee account.”
The issue has been known to Microsoft since last six years, so it’s likely the company doesn’t consider it a security flaw as it requires local admin rights on the computer, and deems this is how its operating system is supposed to behave.