TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

NTFS direct read allows for elevation of privilege (CVE-2020-16938)

1 pointsby a5withtrrsover 4 years ago

1 comment

a5withtrrsover 4 years ago
This bug is pretty novel as far as I&#x27;m aware. A recent update to Windows means that non administration users can access partition and volume device objects which bypasses the usual file restrictions on special files like SAM&#x2F;Security files. Easily tested using 7-zip as it natively supports direct access. Strangely, Microsoft took a bit of prodding to acknowledge this issue[1]. [1] <a href="https:&#x2F;&#x2F;twitter.com&#x2F;jonasLyk&#x2F;status&#x2F;1316130500667412482" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;jonasLyk&#x2F;status&#x2F;1316130500667412482</a>