AI DevwWrld CyberDSA Chatbot Summit Cyber Revolution Summit CYSEC Global Cyber Security & Cloud Expo World Series Digital Identity & Authentication Summit Asian Integrated Resort Expo Middle East Low Code No Code Summit TimeAI Summit

Patched critical security vulnerability in Windows: details emerge

The exploit, now fixed, gave attackers potential access to system privileges. Cybersecurity firm Numen Cyber reveals how the important loophole could have been exploited

This pill is also available in Italian language

Details are emerging about a now-fixed security vulnerability that was being actively exploited in Microsoft Windows. This could be used by a threat actor to gain elevated privileges on affected systems. This vulnerability, identified as CVE-2023-29336, has been rated with a severity rating of 7.8 and concerns an elevation of privilege bug in the Win32k component of Windows.

The potential impact of the vulnerability

Microsoft revealed via an advisory as part of Patch Tuesday updates last month: "An attacker who successfully exploited this vulnerability could have gained system privileges." Avast security experts Jan Vojtěšek, Milánek and Luigino Camastra were recognized for discovering and reporting the vulnerability. The Win32k.sys kernel-mode driver is an essential component of the Windows architecture, responsible for the graphical device interface (GUI) and window management.

Bug analysis and exploitation

At this time, the exact specifics regarding the abuse of the vulnerability in the wild are not known. However, Numen Cyber has decomposed the patch released by Microsoft to work out a test exploit (PoC) for Windows Server 2016. The Singapore-based cybersecurity firm revealed that the vulnerability exploited the leaked kernel address in heap memory to get finally a read-write primitive.

Hopes for the future and new security approaches

“Win32k vulnerabilities are well known in history,” commented Numen Cyber. "However, in the latest Windows 11 preview release, Microsoft attempted to restructure this part of the kernel code using Rust. This may eliminate such vulnerabilities in the new system in the future." Numen Cyber distinguishes itself from typical Web3 security firms by emphasizing the need for advanced security capabilities, with a particular focus on attack and defense capabilities at the operating system level. Their products and services offer cutting-edge solutions to address the unique security challenges of Web3.

Follow us on Threads for more pills like this

06/08/2023 22:26

Editorial AI

Complementary pills

Microsoft addresses 73 software vulnerabilities on June 2023 Patch TuesdayTech giant fixes a number of critical security flaws, including a Chromium zero-day bug, in its latest update

Last pills

Serious vulnerability discovered in Rabbit R1: all user data at riskVulnerability in Rabbit R1 exposes sensitive API keys. What are the privacy risks?

Cyber attack in Indonesia: the new Brain Cipher ransomware brings services to their kneesNew ransomware hits Indonesia: learn how Brain Cipher crippled essential services and the techniques used by hackers

Patelco Credit Union: security incident halts customer services in CaliforniaService disruption and customer frustration: Patelco Credit Union works to resolve security incident

Cyber attack on TeamViewer: immediate response and investigations underwayStrengthened security measures and international collaborations to counter the cyber threat