Skip to main content

Bypassing Windows Administrator Protection

0
High
Vulnerabilitywindowsmalware
Published: 01/26/2026 (01/26/2026, 08:00:00 UTC)
Source: Google Project Zero

Description

Windows 11 25H2 introduced a new Administrator Protection feature designed to replace User Account Control (UAC) with a more secure mechanism for granting administrator privileges. Research identified nine separate vulnerabilities that could bypass this feature to silently gain full administrator privileges. All reported issues have been fixed by Microsoft either before the official release or in subsequent security updates. As of December 2025, Microsoft temporarily disabled Administrator Protection due to an unrelated application compatibility issue. The feature aims to address longstanding weaknesses in UAC, which allowed silent privilege escalation through various bypass techniques. The new mechanism enforces a stronger security boundary between limited and administrator privileges.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/04/2026, 12:59:15 UTC

Technical Analysis

Administrator Protection in Windows 11 25H2 is a security feature intended to replace UAC by providing a more robust and securable system for local users to gain administrator privileges only when necessary. The research detailed nine distinct vulnerabilities that could bypass this protection to silently escalate privileges. These vulnerabilities were responsibly disclosed to Microsoft and have been fixed either in optional update KB5067036 or later security bulletins. The feature was temporarily disabled in December 2025 due to an unrelated compatibility issue. The feature addresses fundamental design flaws in UAC, such as shared user profiles and token impersonation weaknesses, and aims to prevent silent elevation of privileges that malware has exploited for years. The research and fixes improve the security boundary for administrator privilege elevation on Windows 11.

Potential Impact

If exploited, the vulnerabilities allowed a local user to silently gain full administrator privileges, bypassing the intended security boundary of Administrator Protection. This could enable unauthorized system modifications and elevate malware capabilities. However, all identified vulnerabilities have been fixed by Microsoft prior to or shortly after the feature's official release. The temporary disabling of Administrator Protection is unrelated to these vulnerabilities and does not affect the security fixes. There are no known exploits in the wild for these issues.

Mitigation Recommendations

All vulnerabilities described have been fixed by Microsoft in optional update KB5067036 and subsequent security bulletins. Users should ensure their Windows 11 systems are fully updated with the latest patches. The Administrator Protection feature is currently disabled by Microsoft due to an unrelated compatibility issue; monitor official Microsoft communications for re-enablement updates. No additional action is required beyond applying official updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.7,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://projectzero.google/2026/26/windows-administrator-protection.html","fetched":true,"fetchedAt":"2026-08-04T12:57:56.165Z","wordCount":4569}

Threat ID: 6a71e1d4bf8831d539d38869

Added to database: 08/04/2026, 12:57:56 UTC

Last enriched: 08/04/2026, 12:59:15 UTC

Last updated: 09/17/2026, 02:29:34 UTC

Views: 53

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses