Summary

Member-only story 🎯 The 8,000 bounty and recognized in the MSRC Hall of Fame (May 2026) for an Elevation of Privilege (EoP) vulnerability in Microsoft Edge. I didn’t use a zero-day memory corruption or a complex sandbox escape. Instead, I used a feature that Windows has supported for decades: the humble NTFS Directory Junction. Here is the story of how I tricked Microsoft Edge into doing my dirty work. 🔍 The Hunter’s Mindset: Why Look Here? My recent security research heavily involved directory poisoning and symlink manipulations. That deep dive rewired my brain to constantly question how highly privileged applications interact with local file paths. I started observing Microsoft Edge’s background routines. Like all modern browsers, Edge runs scheduled cleanup and file-handling tasks. Some of these routines run with elevated privileges to manage system-level…

By Sachin Patil

Original Article