This is a big issue in enterprise deployments. Consider, for example, the Sony hack - this is the kind of issue that allows a savvy low-level employee to wreak havoc on their employer, because once you can get root on a machine inside a corporate network, all kinds of doors open.
This isn't a remote root code execution bug, but it shouldn't be taken lightly, either. The exact environments where this bug would be applicable (locked-down) are the environments that could suffer severe damage because of an escalation issue.
The thing is, though, local privilege escalation isn't new, and it isn't novel. This is one in a long string of many, many similar bugs across most every major platform. It's completely unremarkable except for the reluctance on MS's part to patch it in a reasonable timeframe.
Comments
This is a big issue in enterprise deployments. Consider, for example, the Sony hack - this is the kind of issue that allows a savvy low-level employee to wreak havoc on their employer, because once you can get root on a machine inside a corporate network, all kinds of doors open.
This isn't a remote root code execution bug, but it shouldn't be taken lightly, either. The exact environments where this bug would be applicable (locked-down) are the environments that could suffer severe damage because of an escalation issue.
The thing is, though, local privilege escalation isn't new, and it isn't novel. This is one in a long string of many, many similar bugs across most every major platform. It's completely unremarkable except for the reluctance on MS's part to patch it in a reasonable timeframe.