Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Google researcher exposes unpatched Windows 8.1 security flaw

Google researcher exposes unpatched Windows 8.1 security flaw

Dave W. Shanahan Dave W. Shanahan
December 13, 2019
2 min read

A Google researcher by the name ‘forshaw’ found and reported a privilege escalation bug in Windows 8.1. Forshaw even reveals a PoC (Proof of Concept) program for the Windows 8.1 weakness. In it, forshaw details how to take advantage of the Windows 8.1 bug:

The PoC has been tested on Windows 8.1 update, both 32 bit and 64 bit versions. I’d recommend running on 32 bit just to be sure. To verify perform the following steps:

1) Put the AppCompatCache.exe and Testdll.dll on disk

2) Ensure that UAC is enabled, the current user is a split-token admin and the UAC setting is the default (no prompt for specific executables).

3) Execute AppCompatCache from the command prompt with the command line “AppCompatCache.exe c:\\windows\\system32\\ComputerDefaults.exe testdll.dll”.

4) If successful then the calculator should appear running as an administrator. If it doesn’t work first time (and you get the ComputerDefaults program) re-run the exploit from 3, there seems to be a caching/timing issue sometimes on first run.

This bug is subject to a 90 day disclosure deadline. If 90 days elapse without a broadly available patch, then the bug report will automatically become visible to the public.

Forshaw does not indicate whether the bug is present in earlier versions of Windows, but the ability to get administrator privileges certainly presents a problem for Microsoft Windows security. A Microsoft spokesperson responded to this threat today in a statement:

We are working to release a security update to address an Elevation of Privilege issue. It is important to note that for a would-be attacker to potentially exploit a system, they would first need to have valid logon credentials and be able to log on locally to a targeted machine. We encourage customers to keep their anti-virus software up to date, install all available Security Updates and enable the firewall on their computer.

I think Google or the Google researcher forshaw should have notified Microsoft of the bug as it appears that Microsoft was completely caught off-guard by its public release. However, I guess it is up to Microsoft to make sure that Windows 8.1 is as secure as possible, and should probably investigate to see if there any are other security flaws that may make Windows 8.1 vulnerable in the future.

Let us know what you think in the comments below! 

Further reading: Google, Microsoft, Windows 8.1, ZDNET

Share this article:
Tags:
Google Microsoft Windows 8.1 ZDNET
Previous Article ComScore: Combined Microsoft and Yahoo U.S. search share stuck at 28 percent Next Article Scroogled: Google believes there is no legitimate expectation of privacy in emails

Related Articles

Installing Web Apps in Chrome May Soon Take More Than One Click

March 17, 2026
Nvidia CEO Jensen Huang says demand for Blackwell and Rubin AI chips could reach $1 trillion as AI infrastructure spending grows rapidly.

Nvidia CEO Jensen Huang sees $1 trillion demand for Blackwell and Rubin AI chips

March 16, 2026
Nvidia introduces DLSS 5 to improve game realism with generative AI

Nvidia introduces DLSS 5 to improve game realism with generative AI

March 16, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Installing Web Apps in Chrome May Soon Take More Than One Click
  • Nvidia CEO Jensen Huang sees $1 trillion demand for Blackwell and Rubin AI chips
  • Nvidia introduces DLSS 5 to improve game realism with generative AI
  • Dictionary Publisher Files Copyright Lawsuit Against OpenAI
  • Shopify exec says AI shopping agents are the future of e-commerce

Recent Comments

No comments to show.
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Installing Web Apps in Chrome May Soon Take More Than One Click
  • Nvidia CEO Jensen Huang sees $1 trillion demand for Blackwell and Rubin AI chips
  • Nvidia introduces DLSS 5 to improve game realism with generative AI
  • Dictionary Publisher Files Copyright Lawsuit Against OpenAI
  • Shopify exec says AI shopping agents are the future of e-commerce

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy