Windows 11 bug disclosed by researcher unhappy with Microsoft bug bounties

Windows 11 Start Laptop Razerbook
Windows 11 Start Laptop Razerbook (Image credit: Daniel Rubino / Windows Central)

What you need to know

  • A researcher has publicly disclosed a zero-day local privilege elevation vulnerability in Windows.
  • The researcher disclosed the vulnerability due to frustration with Microsoft's decreasing payouts for bug bounties.
  • The vulnerability allows a Windows user with Standard privileges to open the command prompt with SYSTEM privileges.

The vulnerability was reportedly publicly disclosed due to frustration with Microsoft's decreasing payouts for bug bounties. The researcher, Abdelhamid Naceri, told Bleeping Computer, "Microsoft bounties [have] been trashed since April 2020, I really wouldn't do that if MSFT didn't take the decision to downgrade those bounties."

This is a common complaint among bug hunters. Microsoft's payouts through its bug bounty program have gone down over the years in many instances.

Microsoft fixed an issue with its November 2021 Patch Tuesday updates, but a related vulnerability remained. Naceri found a bypass to the patch and a more powerful vulnerability. Naceri published a proof-of-concept exploit on GitHub. The GitHub page also explains the vulnerability in more depth.

Bleeping Computer tested the exploit, which proved to be able to gain SYSTEM privileges while on an account with Standard privileges.

A fix for this vulnerability is likely on the way from Microsoft, though the company has not commented on it at this point.

Sean Endicott
News Writer and apps editor

Sean Endicott is a news writer and apps editor for Windows Central with 11+ years of experience. A Nottingham Trent journalism graduate, Sean has covered the industry’s arc from the Lumia era to the launch of Windows 11 and generative AI. Having started at Thrifter, he uses his expertise in price tracking to help readers find genuine hardware value.

Beyond tech news, Sean is a UK sports media pioneer. In 2017, he became one of the first to stream via smartphone and is an expert in AP Capture systems. A tech-forward coach, he was named 2024 BAFA Youth Coach of the Year. He is focused on using technology—from AI to Clipchamp—to gain a practical edge.