Tuesday, April 22, 2025
HomeCVE/vulnerabilityNew Windows 11 Vulnerability Lets Attackers Elevate Privileges

New Windows 11 Vulnerability Lets Attackers Elevate Privileges

Published on

SIEM as a Service

Follow Us on Google News

A new vulnerability has been discovered in Windows 11, specifically affecting the 23H2 version.

This vulnerability is identified in the ksthunk.sys driver, allows attackers to exploit an integer overflow in the CKSAutomationThunk::ThunkEnableEventIrp function to escalate their privileges on the system.

Technical Details

The flaw was highlighted during the TyphoonPWN 2024 event, where an independent security researcher successfully demonstrated an exploit that secured them second place in the competition.

- Advertisement - Google News

Analyze cyber threats with ANYRUN's powerful sandbox. Black Friday Deals : Get up to 3 Free Licenses.

The vulnerability resides in the Kernel Streaming Service’s handling of 32-bit processes on a 64-bit system. Below is an excerpt of the critical portion of the code:

__int64 __fastcall CKSAutomationThunk::ThunkEnableEventIrp(__int64 a1, PIRP a2, __int64 a3, int *a4) {
  …
  outlen_adjust = (outbuflen + 0x17) & 0xFFFFFFF8;
  …
  a2->AssociatedIrp.MasterIrp = (struct _IRP *)ExAllocatePool2( 0x61i64, outlen_adjust + (unsigned int)inbuflen, 1886409547i64);
  …
  if ((unsigned int)outbuflen > 0x10)
    memmove((void *)(data + 0x20), (char *)a2->UserBuffer + 16, outbuflen - 16);
  …
}

According to the SSD report, the specific function ThunkEnableEventIrp improperly handles buffer length calculations, leading to a potential integer overflow.

At the core of the issue is the calculation of outlen_adjust, which is derived from the output buffer length plus a constant, realigned for memory allocation.

Due to the lack of overflow validation, this results in a scenario where a smaller than necessary buffer is allocated, leading to a heap overflow when data is subsequently copied into this buffer.

This heap overflow occurs in the non-paged pool, where specially crafted named pipe techniques can be utilized to exploit the vulnerability further.

By controlling the allocation size and data, attackers can achieve arbitrary read and write capabilities, a crucial step in privilege escalation attacks.

The exploitation process involves several steps:

  1. Memory Spraying: Fill memory with specific patterns using named pipes to predictably allocate system memory.
  2. Trigger Vulnerability: Use the identified flaw to cause a heap overflow, affecting adjacent memory objects like named pipes.
  3. Arbitrary Read and Write: Leverage the memory corruption to gain unauthorized memory access, potentially modifying system-level data structures.
  4. Escalate Privileges: By overwriting tokens in the process’s memory, an attacker can elevate their permissions to those of the SYSTEM account, granting full control over the affected system.

Despite the critical nature of this vulnerability, the vendor’s response has been somewhat ambiguous.

They acknowledged the vulnerability but classified it as a duplicate of a previously fixed issue.

However, during testing on the latest version of Windows 11, the vulnerability was still reproducible, raising concerns about the efficacy of the patching process.

This vulnerability highlights the ongoing challenges in ensuring system security, especially in complex operating system environments like Windows 11.

Users and administrators are advised to apply all available security updates from Microsoft promptly and to remain vigilant for any further advisories concerning this issue.

Meanwhile, security researchers continue to stress the importance of thorough validation in input handling, especially in kernel-level code, to prevent such vulnerabilities from arising.

Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Infostealer Attacks Surge 84% Weekly Through Phishing Emails

The volume of infostealer malware distributed through phishing emails has surged by 84% week-on-week...

North Korean IT Workers Use Real-Time Deepfakes to Infiltrate Organizations Through Remote Jobs

A division of Palo Alto Networks, have revealed a sophisticated scheme by North Korean...

New Phishing Technique Hides Weaponized HTML Files Within SVG Images

Cybersecurity experts have observed an alarming increase in the use of SVG (Scalable Vector...

Detecting And Blocking DNS Tunneling Techniques Using Network Analytics

DNS tunneling is a covert technique that cybercriminals use to bypass traditional network security...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Infostealer Attacks Surge 84% Weekly Through Phishing Emails

The volume of infostealer malware distributed through phishing emails has surged by 84% week-on-week...

North Korean IT Workers Use Real-Time Deepfakes to Infiltrate Organizations Through Remote Jobs

A division of Palo Alto Networks, have revealed a sophisticated scheme by North Korean...

New Phishing Technique Hides Weaponized HTML Files Within SVG Images

Cybersecurity experts have observed an alarming increase in the use of SVG (Scalable Vector...