• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Windows Zero Day Still Circulating After Faulty Fix

Windows Zero-Day Still Circulating After Faulty Fix

You are here: Home / Latest Cyber Security Vulnerabilities / Windows Zero-Day Still Circulating After Faulty Fix
December 24, 2020

The LPE bug could allow an attacker to install systems perspective, alter, or delete info or develop new accounts with full person rights.

A high-severity Windows zero-day that could direct to comprehensive desktop takeover continues to be harmful right after a “fix” from Microsoft failed to sufficiently patch it.

The local privilege-escalation bug in Windows 8.1 and Windows 10 (CVE-2020-0986) exists in the Print Spooler API. It could enable a neighborhood attacker to elevate privileges and execute code in the context of the recent consumer, in accordance to Microsoft’s advisory issued in June. An attacker would to start with have to log on to the technique, but could then run a specially crafted software to take manage of an affected method.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


“The issue occurs due to the fact the Windows kernel fails to adequately deal with objects in memory,” the agency explained. “An attacker who efficiently exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then set up plans perspective, alter, or delete info or make new accounts with entire person rights.”

The bug costs 8.3 out of 10 on the CVSS vulnerability-severity scale.

From a more technological point of view, “the particular flaw exists inside the person-manner printer driver host approach splwow64.exe,” according to an advisory from Craze Micro’s Zero Working day Initiative (ZDI), which described the bug to Microsoft past December. “The issue final results from the lack of good validation of a user-supplied benefit prior to dereferencing it as a pointer.”

The issue remained unpatched for six months. In the meantime, Kaspersky observed it becoming exploited in the wild in May possibly against a South Korean enterprise, as aspect of an exploit chain that also utilized a distant code-execution zero-working day bug in Internet Explorer. That marketing campaign, dubbed Operation Powerfall, was believed to be initiated by the superior persistent threat (APT) identified as Darkhotel.

Microsoft’s June update included a patch that “addresses the vulnerability by correcting how the Windows kernel handles objects in memory.” On the other hand, Maddie Stone, researcher with Google Undertaking Zero, has now disclosed that the resolve was faulty, soon after Microsoft unsuccessful to re-patch it inside of 90 days of being alerted to the difficulty.

“Microsoft released a patch in June, but that patch didn’t fix the vuln,” she tweeted on Wednesday. “After reporting that negative fix in Sept. beneath a 90-day deadline, it is nevertheless not set.”

She additional, “The unique issue was an arbitrary pointer dereference which permitted the attacker to management the src and dest ideas to a memcpy. The ‘fix’ merely altered the pointers to offsets, which continue to permits handle of the args to the memcpy.”

Microsoft has issued a new CVE, CVE-2020-17008, and researchers count on a patch in January. Venture Zero meanwhile has issued public proof-of-thought code for the issue.

Obtain our exclusive Totally free Threatpost Insider E-book Healthcare Security Woes Balloon in a Covid-Period Planet , sponsored by ZeroNorth, to master a lot more about what these security dangers necessarily mean for hospitals at the day-to-day amount and how health care security groups can implement greatest procedures to shield suppliers and individuals. Get the total story and Down load the Book now – on us!

 


Some areas of this write-up are sourced from:
threatpost.com

Previous Post: «Account Takeovers: Insiders Need Not Be Malicious To Cause Chaos Account takeovers: Insiders need not be malicious to cause chaos
Next Post: SolarWinds Hackers “Impacting” State and Local Governments Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.