Windows implements a security mechanism called “Protected Processes” that prevents even administrator-level users from tampering with critical system processes. Many system processes, antivirus solutions, and EDRs use this protection level, including Windows Defender.
When attempting to open a handle to a process using the OpenProcess Windows API function, different access rights can be requested. For protected processes, most access rights are denied by default, even with administrator privileges.
Location: /lib/ajaxHandlers/ajaxDeleteAllLoggingFiles.php
This vulnerability allows deletion of any file by specifying:
path parameterext parameter
