Sandbox privilege escalation

I had the privilege of being warned about one of my games in the new sandbox. Normally this program is run as Guest. After selecting “run normally”, I was shocked to find Avast not in fact running normally (as it was selected to run: as Guest), but instead running my game with the SYSTEM account! This is a SERIOUS bug!

  • what operating system?
  • what exactly is the game?
  • how did you set it up to be run as Guest?
  • what build of avast?

I understand the reason for these template questions as I am a software developer myself. The only necessary one in this case is “How did you produce this issue?”,… which as it happens I’ve already answered, but in case you missed it the first time: It’s easy to reproduce: Just run the “suspicious” program as an underprivileged user. Make sure to explicitly tell avast not to use the sandbox, and watch it execute in the context of SYSTEM.

They aren’t just template questions as that is one of the avast developers asking the questions.

So it is likely he wants to try and replicate the problem.

http://www.geekycode.net/00PS.wmv; Watch the first two minutes. (Everything after that is me trying to reproduce the other bug that I mentioned in the video but failing, giving up… That one mighta been my error)

Template questions? I tried to reproduce - and it didn’t happen, the process was running under the specified user. So, I asked.
If you don’t understand that the behavior might be OS dependent, for example… well, what can I say.

Btw, I’m not really much into “movies” of that kind - but there’s none at the specified URL anyway.