Clear, practical technology insights BSOD Code Lookup · Windows Error Code Lookup · Wi-Fi Troubleshooting · PC Troubleshooting Checklist

Microsoft's Patching Wasn't Thorough, While Google Publicly Disclosed the Windows 11 Security Vulnerability

Explore microsoft's patching wasn't thorough, including the key concepts, practical examples, important considerations, and useful guidance.

Table of Contents

Explore microsoft's patching wasn't thorough, including the key concepts, practical examples, important considerations, and useful guidance.

According to a detailed technical report on the Project Zero bug tracking system, security researcher James Forshaw discovered an Elevation of Privilege (EoP) vulnerability in Windows 11 Insider Preview builds. This vulnerability appears in the Administrator Protection feature – a capability Microsoft is about to implement in Windows 11, allowing for 'on-demand' administrative privileges via Windows Hello and an isolated admin token.

However, during the analysis, Forshaw discovered a vulnerability in Administrator Protection that allowed a low-privileged process to take control of a UI access process, thereby escalating to administrator privileges. Forshaw privately reported this vulnerability to Microsoft on August 8th, giving the company a deadline of November 6th to patch it. After being granted an extension, Microsoft released the patch on November 12th and acknowledged Forshaw's contribution in the CVE-2025-60718 vulnerability.

However, even though the matter seemed closed, Forshaw recently reopened the report, claiming that Microsoft's patch was incomplete and did not thoroughly fix the vulnerability. Since Microsoft did not provide further response, Project Zero decided to publicly disclose the details of this security issue.

Although this vulnerability has been widely publicized, users shouldn't panic. This is a type of local privilege escalation attack, meaning the attacker must have physical access to the computer to run the malware and exploit the vulnerability. Furthermore, Administrator Protection is currently only available on certain Windows 11 Insider builds and must be manually enabled. Therefore, the number of users at risk is currently quite small.

Nevertheless, it is absolutely essential for Microsoft to continue thoroughly investigating Forshaw's findings and patching the vulnerability completely, especially before Administrator Protection is officially released to the public on Windows 11.

Final Thoughts

Understanding microsoft's patching wasn't thorough, while google publicly disclosed the windows 11 security vulnerability makes it easier to evaluate the information and apply the most relevant recommendations. Focus on the key points above and verify details that may change over time.

FAQ

What is microsoft's patching wasn't thorough, while google publicly disclosed the windows 11 security vulnerability?

Explore microsoft's patching wasn't thorough, including the key concepts, practical examples, important considerations, and useful guidance.

What key points does this article cover?

The article explains the core concept, important considerations, and practical details readers should understand.

How can you use this information in practice?

Use the explanations to compare options, verify important details, and make a more informed decision. Apply the recommendations that best match your goals and situation.

Discussion

Reader Comments 0

Sign in with email or Google to join the discussion.