Very recently patched Windows zero-day vulnerability (CVE-2019-0859) in win32k.sys let hackers take control of unpatched Windows systems.
Security researchers from Kaspersky team recent addressed this Zero-day vulnerability in win32k.sys while it made an attempt to exploit one of their customers Microsoft Windows operating system.
A Local Privilege Escalation vulnerability was then reported later to Microsoft and released a patch for Zero-day along with 74 other security vulnerabilities.
This is actually the fifth vulnerability that consecutive exploited Local Privilege Escalation vulnerability in Windows that uncovered by Kaspersky team researchers, here the previous zero-days in very recent past.
This Vulnerability is presented in the CreateWindowEx, a function that
creates an overlapped, pop-up, or child window with an extended style.
Attackers Exploiting this elevation of privilege vulnerability in Windows when Win32k component fails to properly handle objects in memory.
A PowerShell script mainly used by attackers for the post-exploitation process with a Base64 encoded command.
The ultimate goal of this PowerShell script to download a second-stage script from https//pastebin.com.
This Second stage of the PowerShell executes the final stage which is also a PowerShell Script that you can see in below image.
According to Kaspersky, the third script is very simple and does the following:
At the final stage, the shellcode is to make a trivial HTTP reverse shell that leads to attackers gain complete control of the targeted victims Windows system.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.
Unpatched Internet Explorer Zero-day Vulnerability Lets Attackers Hack Windows PC & Steal Files
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert on a…
The Biden administration confirmed that a Chinese state-sponsored hacking group breached the U.S. Treasury Department,…
Security researchers Daan Keuper, Thijs Alkemade, and Khaled Nassar from Computest Sector 7 disclosed a…
Researchers observed a recent surge in activity from the "FICORA" and "CAPSAICIN," both variants of…
The watering hole attack leverages a compromised website to deliver malware. When a user visits…
The NFS protocol offers authentication methods like AUTH_SYS, which relies on untrusted user IDs, and…