A researcher discovered new double Zero-day exploit that affected Adobe Acrobat, Reader and older Windows 7 platforms, Windows Server 2008.
This critical Zero-Day exploit discovered during the analysis conducted by Microsoft against the malicious PDF file that discovered by ESET researcher.
The malicious PDF initially reported to Microsoft as a potential exploit for an unknown Windows kernel vulnerability but the detailed research leads to find another 2 new zero-day exploit within the same PDF.
Initially, this malicious PDF discovered from virustotal which is uploaded by someone. At that time it wasn’t fully prepared to attack and the exploit was in an earlier stage of the development.
Among these 2 critical zero-day exploits, first exploit attacks the Adobe JavaScript engine and run the shellcode and the second exploit affected the older version of Windows 7.
Adobe Acrobat and Reader based Exploit distributed via malicious PDF as a JPEG 2000 stream that contains the Javascript exploit code.
Later malicious JPEG 2000 stream triggers an out-of-bounds access operation and the access operation is called upon out-of-bounds memory laid out by the heap spray.
After that corrupted vftable transfers execution into ROP chains then it transfers it into main shellcode.
Later main EoP module loads through reflective DLL loading and finally it launch the Win32k EoP exploit.
After the successful exploitation, it will drop the .vbs file that designed to download additional payloads to compromise the Victims.
A loaded PE module exploits the main Win32k elevation-of-privilege (EoP) that was taking advantages of previously unknown vulnerability that affected the windows 7 machine and not present on Windows 10 and newer products.
This exploits using the NULL page to pass malicious records and copies arbitrary data to an arbitrary kernel location.
Intially exploit calls the DLL NtAllocateVirtualMemory to allocate a fake data structure at the NULL page.
According to Microsoft, the Exploit is working in following ways.
Finally, the exploit modifies the EPROCESS.Token of the shellcode process and bypass the System and gain the access.
You can also read the ESET Research regarding this Double Zero day Exploits.
SHA-256: dd4e4492fecb2f3fe2553e2bcedd44d17ba9bfbd6b8182369f615ae0bd520933
SHA-1: 297aef049b8c6255f4461affdcfc70e2177a71a9+
Zerodium Pays Upto $1,500,000 Per Fully Functional Zeroday Exploit Submissions
Adobe Issues Patch for Critical Flash Player Zero-day Vulnerability : Its Time to Update
Zero-Day Remote Code Execution Vulnerability Discovered in Microsoft Windows JScript
A critical security flaw has been uncovered in certain TP-Link routers, potentially allowing malicious actors…
SilkSpecter, a Chinese financially motivated threat actor, launched a sophisticated phishing campaign targeting e-commerce shoppers…
The research revealed how threat actors exploit SEO poisoning to redirect unsuspecting users to malicious…
Black Basta, a prominent ransomware group, has rapidly gained notoriety since its emergence in 2022…
CVE-2024-52301 is a critical vulnerability identified in Laravel, a widely used PHP framework for building…
A critical vulnerability has been discovered in the popular "Really Simple Security" WordPress plugin, formerly…