WeSearch

MiniPlasma, a Powerful LPE

·1 min read · 0 reactions · 0 comments · 13 views
#cybersecurity#windows#vulnerability#exploit#registry#YellowKey#GreenPlasma#autofstx.exe#Google Project Zero#Windows 11#Windows Insider Preview#WinRE#CVE-2020-17103
⚡ TL;DR · AI summary

Researchers have identified two security vulnerabilities, YellowKey and GreenPlasma, affecting Windows systems. YellowKey involves the 'autofstx.exe' binary present in Windows Update and WinRE images, potentially enabling controlled file deletion during updates. GreenPlasma may allow elevation of privilege by writing to protected registry keys, with evidence suggesting the flaw remains unpatched in current Windows 11 versions.

Key facts
Original article
Blogspot
Read full at Blogspot →
Opening excerpt (first ~120 words) tap to expand

-----BEGIN PGP SIGNED MESSAGE-----Hash: SHA512Recently two researchers had interesting discoveries regarding YellowKey and GreenPlasma,The YellowKey is caused by the binary "autofstx.exe" which propagates all present volumes for transaction files, a researcher (unsure if they want to be named) told me that this binary is also present in windows update WinRE images and I think they will definitely have the same vulnerability as well. However, I'm unsure if it's possible to trigger the controlled file deletion when windows is updating.

Excerpt limited to ~120 words for fair-use compliance. The full article is at Blogspot.

Anonymous · no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments

More from Blogspot