Microsoft Investigating LocalSystem Access Bug

Security personnel in Redmond are investigating a newly reported zero-day bug vulnerability in Microsoft operating systems and server systems. The bug, disclosed Thursday by Bill Sisk, security response communications manager for Microsoft, allows escalation of privilege to occur for authenticated users under specific conditions.

Users on a given system can elevate their access privileges to LocalSystem in Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008, Sisk explained in an e-mail. It could cause havoc by giving an authenticated user inappropriate write, delete, and change privileges.

The fix for this potential problem is still in the works.

"Microsoft has issued Security Advisory (951306) to provide guidance to affected customers to help them protect themselves. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process," Sisk wrote.

The advisory is specifically addressed to IT pros overseeing an environment where several logged-in users provide their own code. Typically, programmers or administrators would have such rights. Specific cases include users working with Microsoft's Internet Information Services, which supports Web-based operational services, and SQL Server.

To address the issue, IT shops should keep at least a cursory, if not detailed, log of daily access to critical systems and applications. A segregation of duties program may be helpful too. Under such a regimen, programmers aren't deploying applications in a live production environment, and neither are the testers of those applications.

In the security advisory, Microsoft contends that companies providing space on their servers for use by off-site clients, or hosting providers, "may be at increased risk from this elevation of privilege vulnerability."

About the Author

Jabulani Leffall is a business consultant and an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others. He consulted for Deloitte & Touche LLP and was a business and world affairs commentator on ABC and CNN.

Featured

  • two large brackets facing each other with various arrows, circles, and rectangles flowing between them

    1EdTech Partners with DXtera to Support Ed Tech Interoperability

    1EdTech Consortium and DXtera Institute have announced a partnership aimed at improving access to learning data in postsecondary and higher education.

  • Abstract geometric shapes including hexagons, circles, and triangles in blue, silver, and white

    Google Launches Its Most Advanced AI Model Yet

    Google has introduced Gemini 2.5 Pro Experimental, a new artificial intelligence model designed to reason through problems before delivering answers, a shift that marks a major leap in AI capability, according to the company.

  •  laptop on a clean desk with digital padlock icon on the screen

    Study: Data Privacy a Top Concern as Orgs Scale Up AI Agents

    As organizations race to integrate AI agents into their cloud operations and business workflows, they face a crucial reality: while enthusiasm is high, major adoption barriers remain, according to a new Cloudera report. Chief among them is the challenge of safeguarding sensitive data.

  • stylized AI code and a neural network symbol, paired with glitching code and a red warning triangle

    New Anthropic AI Models Demonstrate Coding Prowess, Behavior Risks

    Anthropic has released Claude Opus 4 and Claude Sonnet 4, its most advanced artificial intelligence models to date, boasting a significant leap in autonomous coding capabilities while simultaneously revealing troubling tendencies toward self-preservation that include attempted blackmail.