Overview
Syllabus
Intro
What I'm Going to Talk About
Local System Vulnerabilities are Dead!
System Services and Drivers
Service Privilege Levels
Service Start Mode
Accessible Device Objects
Isolated User Mode
Isolated LSASS
Edge Browser
Microsoft Edge Security
Microsoft Edge and Flash
User Account Control
UAC Auto Elevation Directory Check
Folder Permissions
Elevated Token Impersonation
If You Change Task Manager Needs a Prompt
Windows Symbolic Links
Mitigated in Sandboxes
Win32k Hardening
User Mode Font Driver
Process Silos
Opening Device Object
Replace the Root Object Directory
Public Service Announcement
Conclusions
Good Old Issue 222
Taught by
44CON Information Security Conference