Sunday, January 26, 2025
HomeComputer SecurityNewly Patched Windows Zero-day Lets Hackers Take Complete Control of the Windows...

Newly Patched Windows Zero-day Lets Hackers Take Complete Control of the Windows System

Published on

SIEM as a Service

Follow Us on Google News

Very recently patched Windows zero-day vulnerability (CVE-2019-0859) in win32k.sys let hackers take control of unpatched Windows systems.

Security researchers from Kaspersky team recent addressed this Zero-day vulnerability in win32k.sys while it made an attempt to exploit one of their customers Microsoft Windows operating system.

A Local Privilege Escalation vulnerability was then reported later to Microsoft and released a patch for Zero-day along with 74 other security vulnerabilities.

This is actually the fifth vulnerability that consecutive exploited Local Privilege Escalation vulnerability in Windows that uncovered by Kaspersky team researchers, here the previous zero-days in very recent past.

Zero-day Exploit Process in Windows win32k.sys

This Vulnerability is presented in the CreateWindowEx, a function that
creates an overlapped, pop-up, or child window with an extended style.

Attackers Exploiting this elevation of privilege vulnerability in Windows when Win32k component fails to properly handle objects in memory.

A PowerShell script mainly used by attackers for the post-exploitation process with a Base64 encoded command. 

The ultimate goal of this PowerShell script to download a second-stage script from https//pastebin.com.

This Second stage of the PowerShell executes the final stage which is also a PowerShell Script that you can see in below image.

Windows Zero-day
Third stage PowerShell script

According to Kaspersky, the third script is very simple and does the following:

  • Unpacks shellcode
  • Allocates executable memory
  • Copies shellcode to the allocated memory
  • Calls CreateThread to execute shellcode

At the final stage, the shellcode is to make a trivial HTTP reverse shell that leads to attackers gain complete control of the targeted victims Windows system.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read:

Microsoft Hacked – Hackers Compromised The Microsoft Employee’s Account to Gain Access the Customers Email

Unpatched Internet Explorer Zero-day Vulnerability Lets Attackers Hack Windows PC & Steal Files

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Subaru’s STARLINK Connected Car’s Vulnerability Let Attackers Gain Restricted Access

In a groundbreaking discovery on November 20, 2024, cybersecurity researchers Shubham Shah and a...

Android Kiosk Tablets Vulnerability Let Attackers Control AC & Lights

A security flaw found in Android-based kiosk tablets at luxury hotels has exposed a...

CISA Releases Six ICS Advisories Details Security Issues

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued six Industrial Control Systems (ICS)...

Juniper Routers Exploited via Magic Packet Vulnerability to Deploy Custom Backdoor

A sophisticated cyber campaign dubbed "J-magic" has been discovered targeting enterprise-grade Juniper routers with...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

Nnice Ransomware Attacking Windows Systems With Advanced Encryption Techniques

CYFIRMA's Research and Advisory team has identified a new strain of ransomware labeled "Nnice,"...

Hackers Deliver Ransomware on Windows Via Microsoft Teams Voice Calls

Sophos X-Ops’ Managed Detection and Response (MDR) team has uncovered two highly active threat...

Critical SUSE Linux Distro Injection Vulnerability Allow Attackers Exploits “go-git” Library

A significant security vulnerability, designated CVE-2025-21613, has been discovered in the go-git library, used...